NA
CVSSv3

CVE-2012-0993

CVSSv4: NA | CVSSv3: NA | CVSSv2: 6.8 | VMScore: 780 | EPSS: 0.01699 | KEV: Not Included
Published: 21/02/2012 Updated: 21/11/2024

Vulnerability Summary

Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote malicious users to execute arbitrary PHP code via the viewer_size_image_saved cookie.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zenphoto zenphoto 1.4.2

Exploits

ZENphoto version 142 suffers from PHP code execution, cross site scripting and remote SQL injection vulnerabilities ...