CVE-2009-1650 Information

Description

Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) albumID (2) tagID and (3) photoID parameters to index.html.

Reference

http://secunia.com/advisories/35049 http://www.securityfocus.com/archive/1/503493 http://www.securityfocus.com/bid/34967 https://www.exploit-db.com/exploits/8679

Share on: