CVE-2008-6788

Minddezign Photo Gallery - SQL Injection

Title source: rule

Description

SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by CWH Underground · textwebappsphp
https://www.exploit-db.com/exploits/6819
exploitdb WORKING POC
perlwebappsphp
https://www.exploit-db.com/exploits/6820

Scores

EPSS 0.0073
EPSS Percentile 72.8%

Details

CWE
CWE-89
Status published
Products (1)
minddezign/photo_gallery 2.2
Published May 04, 2009
Tracked Since Feb 18, 2026