Product:

Zenphoto

(Zenphoto)
Repositories https://github.com/zenphoto/zenphoto
#Vulnerabilities 31
Date Id Summary Products Score Patch Annotated
2019-12-31 CVE-2015-5591 SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands. Zenphoto N/A
2019-03-21 CVE-2018-20140 Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters. Zenphoto 6.1
2018-06-26 CVE-2018-0610 Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information. Zenphoto 7.2
2017-07-25 CVE-2015-5594 The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string. Zenphoto 6.1
2015-05-31 CVE-2015-2949 Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Zenphoto N/A
2015-05-31 CVE-2015-2948 Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Zenphoto N/A
2012-07-05 CVE-2012-2641 Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3 allows remote attackers to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library. Zenphoto N/A
2012-02-21 CVE-2012-0995 Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH_INFO to zp-core/admin.php, or (4) album parameter to zp-core/admin-edit.php. Zenphoto N/A
2012-02-21 CVE-2012-0994 SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter. Zenphoto N/A
2012-02-21 CVE-2012-0993 Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote attackers to execute arbitrary PHP code via the viewer_size_image_saved cookie. Zenphoto N/A