CVE Vulnerabilities

CVE-2006-2214

Published: May 05, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.

Affected Software

NameVendorStart VersionEnd Version
Image_gallery_management_system4images*1.7.2 (including)
Image_gallery_management_system4images1.7.1 (including)1.7.1 (including)

References