CVE-2005-1079

zOOm Media Gallery 2.1.2 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1079. PoCs published by Andreas Constantinides.

AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in zOOm Media Gallery version 2.1.2, where the 'catid' parameter is not properly sanitized. The example URL demonstrates a basic SQLi payload that could be used to exploit the vulnerability.

Description

SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Andreas Constantinides · textwebappsphp
https://www.exploit-db.com/exploits/25379

The provided text describes a SQL injection vulnerability in zOOm Media Gallery version 2.1.2, where the 'catid' parameter is not properly sanitized. The example URL demonstrates a basic SQLi payload that could be used to exploit the vulnerability.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: zOOm Media Gallery 2.1.2
No auth needed
Prerequisites: Access to the target application's URL
mistral-large-3 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14929
Exploit, Vendor Advisory x_refsource_misc
http://www.securiteam.com/unixfocus/5LP0G0AFFY.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111340031132596&w=2

Scores

EPSS 0.0116
EPSS Percentile 64.1%

Details

Status published
Published May 02, 2005
Tracked Since Feb 18, 2026