Vendorsben3w2bgalall versions
Vulnerabilities

ben3w 2bgal

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2006-5505
Multiple PHP file inclusion vulnerabilities in 2BGal 3.0 allow remote attackers to execute arbitrary PHP code via the lang parameter to (1) admin/configuration.inc.php, (2) admin/creer_album.inc.php, (3) admin/changepwd.php.inc, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Published 2006-10-25 · Modified
7.51 PoCEPSS 0.028
CVE-2007-1852
Multiple PHP remote file inclusion vulnerabilities in 2BGal 3.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the lang_filename parameter to (1) index.php or (2) backupdb.inc.php in admin/, or other unspecified files, different vectors than CVE-2006-5505. NOTE: this issue has been disputed by CVE, since the lang_filename variable is defined before it is used
Published 2007-04-03 · Modified
6.8EPSS 0.013
CVE-2004-1415
SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote attackers to execute arbitrary SQL commands via the id_album parameter.
Published 2005-02-12 · Modified
5.01 PoCEPSS 0.012