Vulnerabilities > Phpwebgallery > Phpwebgallery

DATE CVE VULNERABILITY TITLE RISK
2006-04-03 CVE-2006-1600 SQL-Injection vulnerability in PHPwebgallery 1.4.1
SQL injection vulnerability in category.php in PhpWebGallery 1.4.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
network
low complexity
phpwebgallery
7.5
2005-12-14 CVE-2005-4228 SQL Injection vulnerability in PHPwebgallery
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php.
network
low complexity
phpwebgallery CWE-89
7.5
2002-12-31 CVE-2002-2064 Unspecified vulnerability in PHPwebgallery 1.0
isadmin.php in PhpWebGallery 1.0 allows remote attackers to gain administrative access via by setting the photo_login cookie to pseudo.
network
low complexity
phpwebgallery
7.5