Imagevue is a focused image gallery and media management application with a narrow product footprint but notable prominence in its niche, with its disclosure history centered on the single Imagevue product itself. Observed vulnerability classes span cross-site scripting and miscellaneous input-handling weaknesses characteristic of web-based media applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imagevue over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0700MEDIUM imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions. | Feb 15, 2006 | 5.0 | 25 | NO | YES |
CVE-2006-0701MEDIUM readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters. | Feb 15, 2006 | 5.0 | 25 | NO | YES |
CVE-2006-0702MEDIUM admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the l | Feb 15, 2006 | 5.0 | 25 | NO | YES |
CVE-2008-1273MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) popup.php, (2) test/ | Mar 10, 2008 | 4.3 | 24 | NO | YES |
CVE-2006-0703MEDIUM Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when i | Feb 15, 2006 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imagevue.
Media articles that mention a CVE ID that affects a product developed by Imagevue — matched by CVE ID, not by vendor name.