CVE-2009-0445 Information

Description

SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL commands via the exhibition_id parameter in a gallery.viewPhotos action.

Reference

http://osvdb.org/51741 http://secunia.com/advisories/33730 http://www.securityfocus.com/bid/33596 https://exchange.xforce.ibmcloud.com/vulnerabilities/48468 https://www.exploit-db.com/exploits/7968 https://www.exploit-db.com/exploits/9451

Share on: