Vulnerability CVE-2006-1667


Published: 2006-04-07   Modified: 2012-02-12

Description:
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $projectid variable is less than 1, which prevents the $limitquery_s from being set within slides.php.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Crafty syntax image gallery -> Crafty syntax image gallery 

 References:
http://bash-x.net/undef/adv/craftygallery.html
http://bash-x.net/undef/exploits/crappy_syntax.txt
http://www.securityfocus.com/bid/17379
http://www.vupen.com/english/advisories/2006/1239
https://exchange.xforce.ibmcloud.com/vulnerabilities/25654
https://www.exploit-db.com/exploits/1645

Copyright 2024, cxsecurity.com

 

Back to Top