Search CVE reports


Toggle filters

21 – 26 of 26 results


CVE-2019-12385

Medium priority
Fixed

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database...

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release
Show less packages

CVE-2017-18375

Medium priority
Vulnerable

Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2008-4796

Medium priority

Some fixes available 2 of 23

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote...

10 affected packages

ampache, gforge-plugin-scmcvs, libphp-snoopy, magpierss, mahara...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache
gforge-plugin-scmcvs
libphp-snoopy
magpierss
mahara
mediamate
moodle
opendb
pixelpost
wordpress
Show all 10 packages Show less packages

CVE-2008-3929

Negligible priority
Ignored

gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache
Show less packages

CVE-2007-4438

Medium priority

Not in release

Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache
Show less packages

CVE-2007-4437

Medium priority

Not in release

SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match parameter. NOTE: some details are obtained from third party information.

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache
Show less packages