CVE Vulnerabilities

CVE-2006-5206

Published: Oct 10, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.

Affected Software

NameVendorStart VersionEnd Version
Invision_galleryInvision_power_services*2.0.7 (including)
Invision_galleryInvision_power_services1.0.1 (including)1.0.1 (including)
Invision_galleryInvision_power_services1.3 (including)1.3 (including)
Invision_galleryInvision_power_services1.3.1 (including)1.3.1 (including)
Invision_galleryInvision_power_services2.0.3 (including)2.0.3 (including)
Invision_galleryInvision_power_services2.0.6 (including)2.0.6 (including)

References