Vulnerabilities > CVE-2006-1659 - SQL Injection vulnerability in Softbiz Image Gallery

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
softbiz
exploit available

Summary

Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in images.php. This vulnerability most likely affects all versions of Softbiz, Image Gallery.

Vulnerable Configurations

Part Description Count
Application
Softbiz
1

Exploit-Db

  • descriptionSoftBiz Image Gallery 0 mage_desc.php Multiple Parameter SQL Injection. CVE-2006-1659. Webapps exploit for php platform
    idEDB-ID:27542
    last seen2016-02-03
    modified2006-03-31
    published2006-03-31
    reporterLinux_Drox
    sourcehttps://www.exploit-db.com/download/27542/
    titleSoftBiz Image Gallery - mage_desc.php Multiple Parameter SQL Injection
  • descriptionSoftBiz Image Gallery 0 template.php provided Parameter SQL Injection. CVE-2006-1659 . Webapps exploit for php platform
    idEDB-ID:27543
    last seen2016-02-03
    modified2006-03-31
    published2006-03-31
    reporterLinux_Drox
    sourcehttps://www.exploit-db.com/download/27543/
    titleSoftBiz Image Gallery - template.php provided Parameter SQL Injection
  • descriptionSoftBiz Image Gallery 0 insert_rating.php img_id Parameter SQL Injection. CVE-2006-1659. Webapps exploit for php platform
    idEDB-ID:27545
    last seen2016-02-03
    modified2006-03-31
    published2006-03-31
    reporterLinux_Drox
    sourcehttps://www.exploit-db.com/download/27545/
    titleSoftBiz Image Gallery - insert_rating.php img_id Parameter SQL Injection
  • descriptionSoftBiz Image Gallery 0 suggest_image.php cid Parameter SQL Injection. CVE-2006-1659. Webapps exploit for php platform
    idEDB-ID:27544
    last seen2016-02-03
    modified2006-03-31
    published2006-03-31
    reporterLinux_Drox
    sourcehttps://www.exploit-db.com/download/27544/
    titleSoftBiz Image Gallery - suggest_image.php cid Parameter SQL Injection
  • descriptionSoftBiz Image Gallery 0 images.php cid Parameter SQL Injection. CVE-2006-1659. Webapps exploit for php platform
    idEDB-ID:27546
    last seen2016-02-03
    modified2006-03-31
    published2006-03-31
    reporterLinux_Drox
    sourcehttps://www.exploit-db.com/download/27546/
    titleSoftBiz Image Gallery - images.php cid Parameter SQL Injection