CVE-2007-6362

RSGallery <2.0 beta 5 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by K-159 · textwebappsphp
https://www.exploit-db.com/exploits/4691

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4691
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26704
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/484606/100/100/threaded

Scores

EPSS 0.0002
EPSS Percentile 3.8%

Details

CWE
CWE-89
Status published
Products (1)
joomla/rs_gallery2 beta_5
Published Dec 15, 2007
Tracked Since Feb 18, 2026