7.5
CVSSv2

CVE-2005-4251

Published: 14/12/2005 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mcgallery mcgallery pro 1.0

mcgallery mcgallery pro 1.1

mcgallery mcgallery pro 2.2

Exploits

source: wwwsecurityfocuscom/bid/15845/info mcGallery PRO is prone to multiple input validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input Successful exploitation of these vulnerabilities could result in a compromise of the application,arbitrary local file inclusion an ...
source: wwwsecurityfocuscom/bid/15845/info mcGallery PRO is prone to multiple input validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input Successful exploitation of these vulnerabilities could result in a compromise of the application,arbitrary local file inclusion ...