Summary
Detail | |||
---|---|---|---|
Vendor | Invision Power Services | First view | 2004-12-31 |
Product | Invision Gallery | Last view | 2008-01-23 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
Related : CVE
Date | Alert | Description | |
---|---|---|---|
7.5 | 2008-01-23 | CVE-2008-0421 | SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command. |
7.5 | 2006-12-07 | CVE-2006-6370 | SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and possibly have other impacts, as demonstrated using a "SELECT BENCHMARK" statement in the img parameter in a doaddcomment operation in index.php. |
7.5 | 2006-10-10 | CVE-2006-5206 | SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used. |
5 | 2006-10-10 | CVE-2006-5205 | Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used. |
6.4 | 2006-05-04 | CVE-2006-2202 | SQL injection vulnerability in post.php in Invision Gallery 2.0.6 allows remote attackers to execute arbitrary SQL commands via the album parameter. |
4.3 | 2005-11-02 | CVE-2005-3477 | Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due to CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Invision Gallery. |
7.5 | 2005-11-01 | CVE-2005-3395 | SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter. |
7.5 | 2005-06-09 | CVE-2005-1948 | Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo. |
7.5 | 2004-12-31 | CVE-2004-1835 | Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
40961 | Invision Gallery rate Command album Parameter SQL Injection |
32040 | Invision Gallery forum/modules/gallery/post.php img Parameter SQL Injection DoS |
29717 | Invision Gallery index.php album Parameter SQL Injection |
29716 | Invision Gallery index.php dir Variable Traversal Arbitrary File Disclosure |
25231 | Invision Gallery post.php album Parameter SQL Injection |
20419 | Invision Gallery index.php st Parameter SQL Injection |
20248 | Microsoft IE Embedded Content Processing XSS |
17244 | Invision Gallery Photo Voting SQL Injection |
17243 | Invision Gallery editcomment Command comment Parameter SQL Injection |
4472 | Invision Gallery Module index.php Multiple Parameter SQL Injection |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2006-10-14 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-925.nasl - Type: ACT_GATHER_INFO |
2006-10-14 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-958.nasl - Type: ACT_GATHER_INFO |
2005-11-01 | Name: The remote web server contains a PHP script that is affected by a SQL injecti... File: invision_gallery_st_sql_injection.nasl - Type: ACT_ATTACK |
2005-06-10 | Name: The remote web server contains a PHP application that is vulnerable to multip... File: invision_gallery_sql_injection.nasl - Type: ACT_ATTACK |