7.5
CVSSv2

CVE-2006-2912

Published: 09/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote malicious users to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID parameter to (c) popup.php, or (3) username and (4) password parameters to (d) admin/member.php.

Vulnerable Product Search on Vulmon Subscribe to Product

out of the trees web design selectapix 1.31

Exploits

Secunia Research has discovered some vulnerabilities in SelectaPix version 131, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks ...