CVE Database
/

CVE-2005-4228

Back to search

CVE-2005-4228

Published: Dec 14, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.

VendorProductVersions

n/a

n/a

affected
n/a

References

21690
vdb-entry
x_refsource_OSVDB
18019
third-party-advisory
x_refsource_SECUNIA
ADV-2005-2881
vdb-entry
x_refsource_VUPEN
15837
vdb-entry
x_refsource_BID
21691
vdb-entry
x_refsource_OSVDB
21689
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now