Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor 4images Subscribe
Filtered by product Image Gallery Management System
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0899 1 4images 1 Image Gallery Management System 2018-10-18 7.5 HIGH N/A
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.
CVE-2006-2214 1 4images 1 Image Gallery Management System 2017-07-19 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.