Vendors4homepages4imagesany version
Vulnerabilities

4homepages 4images any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2009-2132
Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter.
Published 2009-06-19 · Modified
6.81 PoCEPSS 0.021
CVE-2015-7708
Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php.
Published 2015-10-05 · Modified
4.3EPSS 0.014
CVE-2009-2131
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a picture.
Published 2009-06-19 · Modified
3.51 PoCEPSS 0.016