Vulnerabilities > CVE-2006-2749 - Input Validation vulnerability in Open Searchable Image Catalogue

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
open-searchable-image-catalogue

Summary

SQL injection vulnerability in search.php in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject arbitrary SQL commands via the (1) txtCustomField and (2) CustomFieldID array parameters. Upgrade to version 0.7.0.1

Vulnerable Configurations

Part Description Count
Application
Open_Searchable_Image_Catalogue
1