CVE-2006-1659
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4)…
Does this matter?
Lower severity and a low EPSS score (2.20%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in images.php.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- softbizscripts/image gallery script
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19523Vendor Advisory
- http://www.osvdb.org/24368Broken Link
- http://www.osvdb.org/24369Broken Link
- http://www.osvdb.org/24370Broken Link
- http://www.osvdb.org/24371Broken Link
- http://www.osvdb.org/24372Broken Link
- http://www.securityfocus.com/archive/1/429763/100/0/threadedBroken Link
- http://www.securityfocus.com/bid/17339Exploit
- http://www.vupen.com/english/advisories/2006/1217Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25616Third Party Advisory
- http://secunia.com/advisories/19523Vendor Advisory
- http://www.osvdb.org/24368Broken Link
- http://www.osvdb.org/24369Broken Link
- http://www.osvdb.org/24370Broken Link
- http://www.osvdb.org/24371Broken Link
- http://www.osvdb.org/24372Broken Link
- http://www.securityfocus.com/archive/1/429763/100/0/threadedBroken Link
- http://www.securityfocus.com/bid/17339Exploit
- http://www.vupen.com/english/advisories/2006/1217Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25616Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.