CVE-2008-2817 Information

Description

SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.

Reference

http://www.securityfocus.com/bid/29753 https://exchange.xforce.ibmcloud.com/vulnerabilities/43100 https://www.exploit-db.com/exploits/5830

Share on: