📦

an_image_gallery

Vendor: plohni

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 0 Remote Access
Total CVEs 4 Total Indexed
Avg. EPSS 2.07% Exploit Prob.
Latest CVE CVE-2009-3367 Sep 24

Security Vulnerability Index

Page 1 / 1
4.3 CVSS
CVE-2009-3367
Exploit Found

Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) index.php and (2) main.php, and the (3) show parameter to main.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: 1.45%
5.0 CVSS
CVE-2009-3366
Exploit Found

Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.

EPSS: 2.69%