Multiple SQL injection vulnerabilities in My Photo Scrapbook 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the key parameter in (1) Displayview.asp and (2) Details_Photo_bv.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
My_photo_scrapbook | My_photo_scrapbook | * | 1.0 (including) |