Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Verosky Media Subscribe
Filtered by product Instant Photo Gallery
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-2079 1 Verosky Media 1 Instant Photo Gallery 2018-10-18 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
CVE-2006-2080 1 Verosky Media 1 Instant Photo Gallery 2018-10-18 6.8 MEDIUM N/A
SQL injection vulnerability in portfolio_photo_popup.php in Verosky Media Instant Photo Gallery 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, which is not cleansed before calling the count_click function in includes/functions/fns_std.php. NOTE: this issue could produce resultant XSS.
CVE-2006-2052 1 Verosky Media 1 Instant Photo Gallery 2018-10-18 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for version 1.0.2 of the product.
CVE-2005-3986 1 Verosky Media 1 Instant Photo Gallery 2017-07-19 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php.