PT-2010-4645 · Unknown · Galeriashqip

Valentin Hoebel

·

Published

2010-09-03

·

Updated

2017-08-17

·

CVE-2010-3207

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GaleriaSHQIP version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible when the magic quotes gpc setting is disabled. The album id parameter is used in the exploitation.
Recommendations For GaleriaSHQIP version 1.0, consider enabling the magic quotes gpc setting to prevent SQL injection attacks. Additionally, restrict access to the "index.php" file until a proper fix is applied, and avoid using the album id parameter in sensitive queries. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3207

Affected Products

Galeriashqip