Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Roxio
Roxio photoshow |
|
| CPEs | cpe:2.3:a:roxio:photoshow:3.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Roxio
Roxio photoshow |
Sat, 27 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 24 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thibaud-rohmer
Thibaud-rohmer photoshow |
|
| CPEs | cpe:2.3:a:thibaud-rohmer:photoshow:3.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Thibaud-rohmer
Thibaud-rohmer photoshow |
Mon, 22 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process. | |
| Title | PhotoShow 3.0 Remote Code Execution via Exiftran Path Injection | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T12:03:25.164Z
Reserved: 2025-12-20T16:31:20.899Z
Link: CVE-2023-53981
Updated: 2025-12-22T21:57:12.271Z
Status : Modified
Published: 2025-12-22T22:16:03.903
Modified: 2025-12-27T17:15:45.927
Link: CVE-2023-53981
No data.
OpenCVE Enrichment
No data.