Vulnerabilities > CVE-2005-3986 - SQL Injection vulnerability in Instant Photo Gallery

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
verosky-media
exploit available

Summary

Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php.

Vulnerable Configurations

Part Description Count
Application
Verosky_Media
1

Exploit-Db

  • descriptionInstant Photo Gallery 1.0 content.php cid Parameter SQL Injection. CVE-2005-3986. Webapps exploit for php platform
    idEDB-ID:26686
    last seen2016-02-03
    modified2005-11-30
    published2005-11-30
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26686/
    titleInstant Photo Gallery 1.0 content.php cid Parameter SQL Injection
  • descriptionInstant Photo Gallery 1.0 portfolio.php cat_id Parameter SQL Injection. CVE-2005-3986. Webapps exploit for php platform
    idEDB-ID:26685
    last seen2016-02-03
    modified2005-11-30
    published2005-11-30
    reporterr0t
    sourcehttps://www.exploit-db.com/download/26685/
    titleInstant Photo Gallery 1.0 portfolio.php cat_id Parameter SQL Injection