Ez-photo-sales
4 CVEs tracked since 2007. Since Aug 2007, none of them reached CISA KEV.
Ez-photo-sales CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2007-08 | 4 | 0 |
Products
The products that kept showing up in Ez-photo-sales's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Ez-photo-sales.
- CVE-2007-4261EZPhotoSales 1.9.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) a file containing cleartext passwords ...7.5
- CVE-2007-4260EZPhotoSales 1.9.3 and earlier has a default "admin" account for galleries, which allows remote attackers to access arbitrary galleries by specifying this username.5.0
- CVE-2007-4259EZPhotoSales 1.9.3 and earlier allows remote attackers to download arbitrary image files via (1) a direct request for a URL under OnlineViewing/galleries/ or (2) navigation of the gallery user inte...5.0
- CVE-2007-4262Unrestricted file upload vulnerability in EZPhotoSales 1.9.3 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP code under OnlineViewing/galleries/.8.5
The record
- Peak rank
- #24 in Aug 2007
- Busiest month shown
- Aug 2007, 4 CVEs
- Months with a KEV entry
- 0 since Aug 2007
- Monthly snapshots
- 1 since 2007