Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
exhibit engine exhibit engine 1.22 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2006-5292
PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the toroot parameter.
Exhibit Engine Exhibit Engine 1.22
Exhibit Engine Exhibit Engine 1.5 Rc4
1 EDB exploit
7.5
CVSSv2
CVE-2005-1875
Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote malicious users to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage parameter.
Exhibit Engine Exhibit Engine 1.22
Exhibit Engine Exhibit Engine 1.54 Rc4
6.8
CVSSv2
CVE-2006-7184
Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote malicious users to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information...
Photography-on-the-net Exhibit Engine 2
2 EDB exploits
10
CVSSv2
CVE-2006-7183
PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the toroot parameter.
Photography-on-the-net Exhibit Engine 2
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3661
open redirect
CVE-2024-25512
CVE-2024-33788
command injection
SSTI
CVE-2024-0043
CVE-2024-29210
CVE-2024-25510
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started