Description
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.
Exploits (2)
References (6)
Core 6
Core References
Exploit vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1009512
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=107997906500032&w=2
Exploit third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/11194
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/9944
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/4472
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15566
Scores
EPSS
0.0095
EPSS Percentile
76.4%
Details
Status
published
Products (1)
invision_power_services/invision_gallery
1.0.1
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026