Vulnerabilities > Phpgraphy > Phpgraphy > 0.9.9a

DATE CVE VULNERABILITY TITLE RISK
2007-02-04 CVE-2006-6966 Remote Security vulnerability in Phpgraphy
phpGraphy before 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by uploading a config.php file via the pictures[] parameter to index.php.
network
low complexity
phpgraphy
7.5
2006-04-20 CVE-2006-1888 Permissions, Privileges, and Access Controls vulnerability in PHPgraphy 0.9.10/0.9.9A
phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php with the editwelcome parameter set to 1, which can then be used to modify the main page to inject arbitrary HTML and web script.
network
phpgraphy CWE-264
6.8
2005-08-30 CVE-2005-2735 Unspecified vulnerability in PHPgraphy 0.9.9A
Cross-site scripting (XSS) vulnerability in phpGraphy 0.9.9a and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.
network
phpgraphy
4.3