7.5
CVSSv2

CVE-2006-2214

Published: 05/05/2006 Updated: 20/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in 4images 1.7.1 and previous versions allow remote malicious users to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.

Vulnerable Product Search on Vulmon Subscribe to Product

4images image gallery management system 1.7.1

4images image gallery management system

Exploits

source: wwwsecurityfocuscom/bid/17748/info 4Images is prone to multiple, unspecified SQL-injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query A successful exploit could allow an attacker to compromise the application, access or modify ...
source: wwwsecurityfocuscom/bid/17748/info 4Images is prone to multiple, unspecified SQL-injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query A successful exploit could allow an attacker to compromise the application, access or modify da ...