7.5
CVSSv2

CVE-2006-5206

Published: 10/10/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Invision Gallery 2.0.7 allows remote malicious users to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.

Vulnerable Product Search on Vulmon Subscribe to Product

invision power services invision gallery 1.3

invision power services invision gallery 1.3.1

invision power services invision gallery 2.0.3

invision power services invision gallery 2.0.6

invision power services invision gallery

invision power services invision gallery 1.0.1

Exploits

/* _ _ _ _ _ __ _ _ _ | || |___| | | |/ /_ _ (_)__ _| |_| |_ ___ | __ / -_) | | ' <| ' \| / _` | ' \ _(_-< |_||_\___|_|_|_|\_\_||_|_\__, |_||_\__/__/ hellknightsvoidru |___/ (c)oded by _1nf3ct0r_ Invision Gallery => 207 ReadFile() & SQL injection exploit +---------- ...