VendorsOut Of The Trees Web Designselectapixall versions
Vulnerabilities

Out Of The Trees Web Design Selectapix

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2006-2912
Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID parameter to (c) popup.php, or (3) username and (4) password parameters to (d) admin/member.php.
Published 2006-06-09 · Modified
7.5EPSS 0.020
CVE-2006-2722
SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources.
Published 2006-06-01 · Modified
7.5EPSS 0.011
CVE-2006-2463
view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter.
Published 2006-05-19 · Modified
5.0EPSS 0.013
CVE-2006-2913
Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows remote attackers to inject arbitrary web script or HTML via the albumID parameter to (1) popup.php and (2) view_album.php.
Published 2006-06-09 · Modified
2.6EPSS 0.021