Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ci parameter to (1) slideshow.asp or (2) thumbnails.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Uphotogallery | Uapplication | 1.1 (including) | 1.1 (including) |