Invision Gallery Index.PHP SQL Injection Vulnerability
BID:20327
Info
Invision Gallery Index.PHP SQL Injection Vulnerability
| Bugtraq ID: | 20327 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5206 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2006 12:00AM |
| Updated: | Feb 01 2008 03:57PM |
| Credit: | _1nf3ct0r_ is credited with the discovery of this vulnerability. |
| Vulnerable: |
Invision Power Services Invision Gallery 2.0.7 Invision Power Services Invision Gallery 2.0.6 Invision Power Services Invision Gallery 2.0.3 Invision Power Services Invision Gallery 1.3.1 Invision Power Services Invision Gallery 1.3 Invision Power Services Invision Gallery 1.0.1 |
| Not Vulnerable: |
Invision Power Services Invision Gallery 2.1 |
Discussion
Invision Gallery Index.PHP SQL Injection Vulnerability
Invision Gallery is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
This issue affects versions prior to Invision Gallery 2.1.0.
Invision Gallery is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
This issue affects versions prior to Invision Gallery 2.1.0.
Exploit / POC
Invision Gallery Index.PHP SQL Injection Vulnerability
Attackers can exploit these issues via a browser.
The following exploits are available:
Attackers can exploit these issues via a browser.
The following exploits are available:
Solution / Fix
Invision Gallery Index.PHP SQL Injection Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Invision Gallery Index.PHP SQL Injection Vulnerability
References:
References:
- Invision Gallery Web Site (Invision Gallery)