5
CVSSv2

CVE-2004-1415

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote malicious users to execute arbitrary SQL commands via the id_album parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ben3w 2bgal 2.4

ben3w 2bgal 2.5.1

Exploits

source: wwwsecurityfocuscom/bid/12083/info A remote SQL injection vulnerability reportedly affects 2Bgal This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an SQL query An attacker may leverage this issue to manipulate SQL query strings and potentially carry out arbitrary ...