CVE-2007-6666

Zenphoto <1.1.3 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Silentz · perlwebappsphp
https://www.exploit-db.com/exploits/4823

Scores

EPSS 0.0037
EPSS Percentile 58.7%

Details

CWE
CWE-89
Status published
Products (4)
zenphoto/zenphoto 1.1
zenphoto/zenphoto 1.1.1
zenphoto/zenphoto 1.1.2
zenphoto/zenphoto 1.1.3
Published Jan 04, 2008
Tracked Since Feb 18, 2026