Lucene search

K

Picturespro Security Vulnerabilities

cve
cve

CVE-2018-5190

PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified cookie, related to pc_head.php, pc_login.php, and...

9.8CVSS

9.2AI Score

0.005EPSS

2018-04-17 01:29 PM
15
cve
cve

CVE-2008-3786

Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka "Gallery or event name" field) in a search...

5.7AI Score

0.002EPSS

2008-08-26 02:41 PM
16
cve
cve

CVE-2008-3788

Multiple SQL injection vulnerabilities in PICTURESPRO Photo Cart 3.9, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) qtitle, (2) qid, and (3) qyear parameters to (a) search.php, and the (4) email and (5) password parameters to (b)...

8.7AI Score

0.002EPSS

2008-08-26 02:41 PM
21
cve
cve

CVE-2008-1536

Cross-site scripting (XSS) vulnerability in index.php in Pictures Pro (aka Tim Grissett) Photo Cart 4.1 allows remote attackers to inject arbitrary web script or HTML via the amessage parameter. NOTE: some of these details are obtained from third party...

5.7AI Score

0.002EPSS

2008-03-28 06:44 PM
20
cve
cve

CVE-2006-6093

Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path...

8AI Score

0.086EPSS

2006-11-24 06:07 PM
21