Vulnerabilities (CVE)

Filtered by vendor Nitropowered Subscribe
Filtered by product Nitro Web Gallery
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-2141 1 Nitropowered 1 Nitro Web Gallery 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands via the PictureId parameter in an open action.
CVE-2008-2817 1 Nitropowered 1 Nitro Web Gallery 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.