Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2007-1469
StatusCandidate
DescriptionSQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
SeverityMedium
CVSS score5,6
CVSS vector(AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N)
PhaseAssigned (16.03.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1469
ReferencesBID : 22988
 BUGTRAQ : 20070315 Absolute Image Gallery Gallery.ASP (categoryid) MSSQL Injection Exploit
 FRSIRT : ADV-2007-1002
 OSVDB : 34239
 SECUNIA : 24543
 XF : absolute-gallery-sql-injection(33005)
SecurityVulns:Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server