Vulnerabilities > Phpwebgallery > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-10-22 CVE-2008-4645 Code Injection vulnerability in PHPwebgallery
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
network
low complexity
phpwebgallery CWE-94
critical
9.0