CVE Vulnerabilities

CVE-2006-2214

Published: May 05, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.

Affected Software

Name Vendor Start Version End Version
Image_gallery_management_system 4images * 1.7.2 (including)
Image_gallery_management_system 4images 1.7.1 (including) 1.7.1 (including)

References