Vulnerabilities > Thomas Rybak

DATE CVE VULNERABILITY TITLE RISK
2006-02-01 CVE-2006-0493 HTML Injection vulnerability in Thomas Rybak MG2 0.5.1
Cross-site scripting (XSS) vulnerability in MG2 (formerly known as Minigal) 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field in a comment associated with a picture.
network
thomas-rybak
4.3
2005-11-02 CVE-2005-3432 Authentication Bypass vulnerability in Thomas Rybak Minigal 2 0.5.1/B13
MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.
network
low complexity
thomas-rybak
5.0