Vulnerabilities > CVE-2006-6187 - SQL-Injection vulnerability in Clicktech Clickgallery 5.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in ClickTech Click Gallery allow remote attackers to execute arbitrary SQL commands via the (1) currentpage or (2) gallery_id parameter to (a) view_gallery.asp, the (3) image_id parameter to (b) download_image.asp, the currentpage or (5) orderby parameter to (c) gallery.asp, or the currentpage parameter to (d) view_recent.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://secunia.com/advisories/23136
- http://securityreason.com/securityalert/1937
- http://www.aria-security.com/forum/showthread.php?t=49
- http://www.securityfocus.com/archive/1/452733/100/0/threaded
- http://www.securityfocus.com/bid/21311
- http://www.vupen.com/english/advisories/2006/4743
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30535