4homepages
4homepages 4images: vulnerabilidades y CVE
4homepages 4images tiene 12 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-50806 | Alta (8.6) | 1.3% | — | 13 ene 2026 | 4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the… |
| CVE-2021-27308 | Media (4.8) | 2.0% | — | 22 mar 2021 | A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter. |
| CVE-2020-35853 | Media (4.8) | 0.59% | — | 26 ene 2021 | 4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user… |
| CVE-2015-7708 | Media (4.3) | 1.4% | — | 5 oct 2015 | Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php. |
| CVE-2012-1023 | Media (5.8) | 1.8% | — | 8 feb 2012 | Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter. |
| CVE-2012-1022 | Alta (7.5) | 1.0% | — | 8 feb 2012 | SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action. |
| CVE-2012-1021 | Media (4.3) | 1.5% | — | 8 feb 2012 | Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action. |
| CVE-2009-2380 | Media (4.3) | 1.1% | — | 8 jul 2009 | Cross-site scripting (XSS) vulnerability in includes/functions.php in 4images 1.7 through 1.7.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the url variable. |
| CVE-2009-2132 | Media (6.8) | 2.1% | — | 19 jun 2009 | Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l… |
| CVE-2009-2131 | Baja (3.5) | 1.6% | — | 19 jun 2009 | Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then… |
| CVE-2006-5236 | Alta (7.5) | 2.1% | — | 11 oct 2006 | SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter. |
| CVE-2006-2011 | Baja (2.6) | 1.3% | — | 25 abr 2006 | Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.