Vulnerabilities
Vulnerable Software
Mcgallery:  Security Vulnerabilities
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.
CVSS Score
5.0
EPSS Score
0.032
Published
2007-03-16
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.
CVSS Score
7.5
EPSS Score
0.104
Published
2006-09-12
Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.
CVSS Score
5.0
EPSS Score
0.039
Published
2005-12-14
Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.
CVSS Score
7.5
EPSS Score
0.006
Published
2005-12-14
Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters.
CVSS Score
4.3
EPSS Score
0.004
Published
2005-12-14
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.
CVSS Score
5.0
EPSS Score
0.004
Published
2005-06-15
Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
CVSS Score
5.0
EPSS Score
0.042
Published
2005-06-15


Contact Us

Shodan ® - All rights reserved