CVE-2005-4228 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since (2) sort_by and (3) items_number parameters to comments.php (4) the search parameter to category.php and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.
Reference
http://pridels0.blogspot.com/2005/12/phpwebgallery-multiple-sql-inj.html http://secunia.com/advisories/18019 http://www.osvdb.org/21689 http://www.osvdb.org/21690 http://www.osvdb.org/21691 http://www.securityfocus.com/bid/15837 http://www.vupen.com/english/advisories/2005/2881
Share on: