Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zenphoto zenphoto vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv2
CVE-2007-0616
Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote malicious users to list arbitrary directories via ".." sequences in the album parameter to index.php.
Zenphoto Zenphoto 1.0.6
Zenphoto Zenphoto 1.0.4
Zenphoto Zenphoto 1.0.5
7.5
CVSSv2
CVE-2011-4825
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager prior to 1.1, as used in tinymce prior to 1.4.2, phpMyFAQ 2.6 prior to 2.6.19 and 2.7 prior to 2.7.1, and possibly other products, allows remote malicious users to inject arbitrary PHP cod...
Phpletter Ajax File And Image Manager 1.0
Phpletter Ajax File And Image Manager 0.5.7
Phpletter Ajax File And Image Manager 0.5.5
Phpletter Ajax File And Image Manager 0.5
Phpletter Ajax File And Image Manager
Phpmyfaq Phpmyfaq 2.7.0
Phpmyfaq Phpmyfaq 2.6.10
Phpmyfaq Phpmyfaq 2.6.5
Phpmyfaq Phpmyfaq 2.6.4
Phpmyfaq Phpmyfaq 2.6.3
Phpletter Ajax File And Image Manager 0.9
Phpletter Ajax File And Image Manager 0.7.10
Phpletter Ajax File And Image Manager 0.6.12
Phpmyfaq Phpmyfaq 2.6.18
Phpmyfaq Phpmyfaq 2.6.16
Phpmyfaq Phpmyfaq 2.6.8
Phpmyfaq Phpmyfaq 2.6.6
Phpmyfaq Phpmyfaq 2.6.2
Phpmyfaq Phpmyfaq 2.6.0
Phpletter Ajax File And Image Manager 0.8.24
Phpletter Ajax File And Image Manager 0.8.9
Phpletter Ajax File And Image Manager 0.8.8
6 EDB exploits
7.5
CVSSv2
CVE-2010-4906
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote malicious users to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.
Zenphoto Zenphoto 1.3
Zenphoto Zenphoto 1.3.1.2
1 EDB exploit
7.5
CVSSv2
CVE-2009-4566
SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote malicious users to execute arbitrary SQL commands via the title parameter in a news action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Zenphoto Zenphoto 1.2.5
1 EDB exploit
7.5
CVSSv2
CVE-2007-6666
SQL injection vulnerability in rss.php in Zenphoto 1.1 up to and including 1.1.3 allows remote malicious users to execute arbitrary SQL commands via the albumnr parameter.
Zenphoto Zenphoto 1.1
Zenphoto Zenphoto 1.1.1
Zenphoto Zenphoto 1.1.2
Zenphoto Zenphoto 1.1.3
1 EDB exploit
6.8
CVSSv2
CVE-2012-0993
Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote malicious users to execute arbitrary PHP code via the viewer_size_image_saved cookie.
Zenphoto Zenphoto 1.4.2
6.8
CVSSv2
CVE-2009-4564
SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote malicious users to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/.
Zenphoto Zenphoto 1.2.5
1 EDB exploit
6.8
CVSSv2
CVE-2006-2187
Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) album and (3) image parameters in index.php.
Zenphoto Zenphoto
Zenphoto Zenphoto 0.9
Zenphoto Zenphoto 1.0 Beta
2 EDB exploits
6.5
CVSSv2
CVE-2020-36079
Zenphoto up to and including 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI. This can, f...
Zenphoto Zenphoto
1 Github repository
6.5
CVSSv2
CVE-2020-5593
Zenphoto versions before 1.5.7 allows an malicious user to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.
Zenphoto Zenphoto
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
CVE-2024-20696
CVE-2024-29829
CVE-2024-33999
CVE-2024-35646
physical
CVE-2024-24919
CVE-2024-31030
local users
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »