Record summary

CVE-2006-5206 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBInvision Gallery 2.0.7 - 'readfile()' / SQL InjectionExploitDB exploitby 1nf3ct0rNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

5