PT-2005-1450 · Gallery · Gallery

Janek Vind

+1

·

Published

2005-02-13

·

Updated

2017-07-11

·

CVE-2005-0377

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SGallery version 1.01
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the idalbum or idimage parameters in the imageview.php file.
Recommendations For SGallery version 1.01, consider restricting access to the imageview.php file until a patch is available, and avoid using the idalbum and idimage parameters in this context to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0377

Affected Products

Gallery