petros

4 exploits Active since Jan 2010
CVE-2009-4564 EXPLOITDB javascript WORKING POC
Zenphoto 1.2.5 - SQL Injection via Category Parameter
SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/.
CVE-2009-4562 EXPLOITDB text WORKING POC
Zenphoto 1.2.5 - Cross-Site Scripting via Admin.php From Parameter
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the from parameter.
CVE-2009-4566 EXPLOITDB javascript WORKING POC
Zenphoto 1.2.5 - SQL Injection via News Title Parameter
SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a news action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2009-4563 EXPLOITDB text WORKING POC
Zenphoto 1.2.5 - Cross-Site Request Forgery via Admin Password Change
Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via the 0-adminpass and 0-adminpass_2 parameters in a saveoptions action.