PT-2006-2584 · Monalbum · Monalbum
Undefined1
·
Published
2006-04-02
·
Updated
2024-02-14
·
CVE-2006-1585
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
MonAlbum version 0.8.7
Description:
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through SQL injection vulnerabilities in multiple parameters, including
pc in index.php, and pnom, pcourriel, pcommentaire in image agrandir.php.Recommendations:
For MonAlbum version 0.8.7, consider restricting access to the
index.php and image agrandir.php files until a patch is available. As a temporary workaround, avoid using the pc, pnom, pcourriel, and pcommentaire parameters in the affected API endpoints.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Monalbum