7.5
CVSSv2

CVE-2008-1162

Published: 05/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote malicious users to execute arbitrary SQL commands via the albumID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

php web scripts dynamic photo gallery 1.0.2

Exploits

Aria-Security Team Aria-SecurityNet ---------------------------- Shoutz: Aura, imm02rtal, NULL, Kinglet And all our staff Vendor: wwwphpwebscriptnet/dynamicphotogallery/foto-galleryphp Original Link: forumaria-securitynet/showthreadphp?p=1521 PoC: albumphp?slideshow=start&albumID=-4214/**/union/**/select/**/0,usern ...