VendorsOut Of The Trees Web Designselectapix1.31
Vulnerabilities

Out Of The Trees Web Design Selectapix 1.31

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2006-2912
Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID parameter to (c) popup.php, or (3) username and (4) password parameters to (d) admin/member.php.
Published 2006-06-09 · Modified
7.5EPSS 0.020
CVE-2006-2463
view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter.
Published 2006-05-19 · Modified
5.0EPSS 0.013
CVE-2006-2913
Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows remote attackers to inject arbitrary web script or HTML via the albumID parameter to (1) popup.php and (2) view_album.php.
Published 2006-06-09 · Modified
2.6EPSS 0.021