CVE-2005-4244

Snipegallery Snipe Gallery < 3.1.4 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/26799
exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/26800

Scores

EPSS 0.0073
EPSS Percentile 72.3%

Classification

CWE
CWE-89
Status draft

Affected Products (1)

snipegallery/snipe_gallery < 3.1.4

Timeline

Published Dec 14, 2005
Tracked Since Feb 18, 2026