CVE-2012-0993

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
21/02/2012
Last modified:
11/04/2025

Description

Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote attackers to execute arbitrary PHP code via the viewer_size_image_saved cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zenphoto:zenphoto:1.4.2:*:*:*:*:*:*:*