7.5
CVSSv2

CVE-2006-6937

Published: 17/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote malicious users to inject arbitrary SQL commands via the sortorder parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

pensacola web designs xtremeasp photogallery 2.0

Exploits

source: wwwsecurityfocuscom/bid/21138/info Xtreme ASP Photo Gallery is prone to multiple input-validation vulnerabilities, including cross-site scripting and SQL-injection issues and an HTML-injection issue because the application fails to properly sanitize user-supplied input Successful exploits of these vulnerabilities could allow an ...