Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
invision power services invision gallery vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-5206
SQL injection vulnerability in Invision Gallery 2.0.7 allows remote malicious users to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.
Invision Power Services Invision Gallery 1.3
Invision Power Services Invision Gallery 1.3.1
Invision Power Services Invision Gallery 2.0.3
Invision Power Services Invision Gallery 2.0.6
Invision Power Services Invision Gallery
Invision Power Services Invision Gallery 1.0.1
1 EDB exploit
NA
CVE-2006-5205
Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote malicious users to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used.
Invision Power Services Invision Gallery 1.3.1
Invision Power Services Invision Gallery 1.0.1
Invision Power Services Invision Gallery 1.3
Invision Power Services Invision Gallery 2.0.6
Invision Power Services Invision Gallery 2.0.7
Invision Power Services Invision Gallery 2.0.3
1 EDB exploit
NA
CVE-2005-1948
Multiple SQL injection vulnerabilities in Invision Gallery prior to 1.3.1 allow remote malicious users to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.
Invision Power Services Invision Gallery 1.0.1
Invision Power Services Invision Gallery 1.3
1 EDB exploit
NA
CVE-2008-0421
SQL injection vulnerability in Invision Gallery 2.0.7 and previous versions allows remote malicious users to execute arbitrary SQL commands via the album parameter in a rate command.
Invision Power Services Invision Gallery
1 EDB exploit
NA
CVE-2004-1835
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote malicious users to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.
Invision Power Services Invision Gallery 1.0.1
2 EDB exploits
NA
CVE-2006-2202
SQL injection vulnerability in post.php in Invision Gallery 2.0.6 allows remote malicious users to execute arbitrary SQL commands via the album parameter.
Invision Power Services Invision Gallery 2.0.6
NA
CVE-2006-6370
SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote malicious users to cause a denial of service and possibly have other impacts, as demonstrated using a "SELECT BENCHMARK" statement in the img parameter in a doaddcommen...
Invision Power Services Invision Gallery 2.0.7
NA
CVE-2005-3395
SQL injection vulnerability in Invision Gallery 2.0.3 allows remote malicious users to execute arbitrary SQL commands via the st parameter.
Invision Power Services Invision Gallery 2.0.3
1 EDB exploit
NA
CVE-2005-3477
Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote malicious users to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due...
Invision Power Services Invision Gallery 2.0.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started