Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Zenphoto
(Zenphoto)Repositories | https://github.com/zenphoto/zenphoto |
#Vulnerabilities | 31 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-12-31 | CVE-2015-5591 | SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands. | Zenphoto | N/A | ||
2019-03-21 | CVE-2018-20140 | Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters. | Zenphoto | 6.1 | ||
2018-06-26 | CVE-2018-0610 | Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information. | Zenphoto | 7.2 | ||
2017-07-25 | CVE-2015-5594 | The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string. | Zenphoto | 6.1 | ||
2015-05-31 | CVE-2015-2949 | Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Zenphoto | N/A | ||
2015-05-31 | CVE-2015-2948 | Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Zenphoto | N/A | ||
2012-07-05 | CVE-2012-2641 | Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3 allows remote attackers to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library. | Zenphoto | N/A | ||
2012-02-21 | CVE-2012-0995 | Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH_INFO to zp-core/admin.php, or (4) album parameter to zp-core/admin-edit.php. | Zenphoto | N/A | ||
2012-02-21 | CVE-2012-0994 | SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter. | Zenphoto | N/A | ||
2012-02-21 | CVE-2012-0993 | Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote attackers to execute arbitrary PHP code via the viewer_size_image_saved cookie. | Zenphoto | N/A |