SQL injection vulnerability in Zoph before 0.7.0.1 might allow remote attackers to execute arbitrary SQL commands via the _order parameter to (1) photos.php and (2) edit_photos.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zoph | Zoph | * | 0.7 (including) |
Zoph | Ubuntu | dapper | * |
Zoph | Ubuntu | devel | * |
Zoph | Ubuntu | edgy | * |
Zoph | Ubuntu | feisty | * |
Zoph | Ubuntu | gutsy | * |
Zoph | Ubuntu | hardy | * |
Zoph | Ubuntu | intrepid | * |
Zoph | Ubuntu | jaunty | * |
Zoph | Ubuntu | karmic | * |