Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
4images vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2009-2131
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and previous versions allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a picture.
4homepages 4images 1.7.1
4homepages 4images 1.7
4homepages 4images 1.6.1
4homepages 4images 1.5
4homepages 4images 1.7.3
4homepages 4images 1.7.6
4homepages 4images 1.0
4homepages 4images 1.7.2
4homepages 4images 1.6
4homepages 4images 1.7.5
4homepages 4images 1.7.4
4homepages 4images
1 EDB exploit
6.8
CVSSv2
CVE-2009-2132
Directory traversal vulnerability in global.php in 4images prior to 1.7.7, when magic_quotes_gpc is disabled, allows remote malicious users to include and execute arbitrary local files via directory traversal sequences in the l parameter.
4homepages 4images 1.6
4homepages 4images 1.5
4homepages 4images 1.7
4homepages 4images 1.7.3
4homepages 4images 1.7.5
4homepages 4images 1.7.4
4homepages 4images 1.0
4homepages 4images
4homepages 4images 1.7.1
4homepages 4images 1.7.2
4homepages 4images 1.6.1
1 EDB exploit
4.3
CVSSv2
CVE-2009-2380
Cross-site scripting (XSS) vulnerability in includes/functions.php in 4images 1.7 up to and including 1.7.7 allows remote malicious users to inject arbitrary web script or HTML via vectors related to the url variable.
4homepages 4images 1.7.6
4homepages 4images 1.7.7
4homepages 4images 1.7.4
4homepages 4images 1.7.5
4homepages 4images 1.7.1
4homepages 4images 1.7
4homepages 4images 1.7.2
4homepages 4images 1.7.3
7.5
CVSSv2
CVE-2006-5236
SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter.
4homepages 4images 1.7.3
4homepages 4images 1.7.1
2 EDB exploits
7.5
CVSSv2
CVE-2006-2214
Multiple SQL injection vulnerabilities in 4images 1.7.1 and previous versions allow remote malicious users to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.
4images Image Gallery Management System 1.7.1
4images Image Gallery Management System
2 EDB exploits
4.3
CVSSv2
CVE-2015-7708
Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php.
4homepages 4images
2.6
CVSSv2
CVE-2006-2011
Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php.
4homepages 4images 1.7
3.5
CVSSv2
CVE-2021-27308
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote malicious users to inject JavaScript via the "redirect" parameter.
4homepages 4images 1.8
4.3
CVSSv2
CVE-2012-1021
Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote malicious users to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action.
4homepages 4images 1.7.10
1 EDB exploit
7.5
CVSSv2
CVE-2012-1022
SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote malicious users to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action.
4homepages 4images 1.7.10
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32744
privilege escalation
CVE-2024-30253
CVE-2024-3914
cross-site scripting
CVE-2024-31497
CVE-2024-3400
CVE-2024-32341
hardcoded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »