This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Invision Power Services First view 2004-12-31
Product Invision Gallery Last view 2008-01-23
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:invision_power_services:invision_gallery:1.0.1:*:*:*:*:*:*:* 5
cpe:2.3:a:invision_power_services:invision_gallery:2.0.3:*:*:*:*:*:*:* 5
cpe:2.3:a:invision_power_services:invision_gallery:1.3:*:*:*:*:*:*:* 4
cpe:2.3:a:invision_power_services:invision_gallery:2.0.6:*:*:*:*:*:*:* 4
cpe:2.3:a:invision_power_services:invision_gallery:2.0.7:*:*:*:*:*:*:* 4
cpe:2.3:a:invision_power_services:invision_gallery:1.3.1:*:*:*:*:*:*:* 3

Related : CVE

  Date Alert Description
7.5 2008-01-23 CVE-2008-0421

SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command.

7.5 2006-12-07 CVE-2006-6370

SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and possibly have other impacts, as demonstrated using a "SELECT BENCHMARK" statement in the img parameter in a doaddcomment operation in index.php.

7.5 2006-10-10 CVE-2006-5206

SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.

5 2006-10-10 CVE-2006-5205

Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used.

6.4 2006-05-04 CVE-2006-2202

SQL injection vulnerability in post.php in Invision Gallery 2.0.6 allows remote attackers to execute arbitrary SQL commands via the album parameter.

4.3 2005-11-02 CVE-2005-3477

Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due to CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Invision Gallery.

7.5 2005-11-01 CVE-2005-3395

SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.

7.5 2005-06-09 CVE-2005-1948

Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.

7.5 2004-12-31 CVE-2004-1835

Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...

Open Source Vulnerability Database (OSVDB)

id Description
40961 Invision Gallery rate Command album Parameter SQL Injection
32040 Invision Gallery forum/modules/gallery/post.php img Parameter SQL Injection DoS
29717 Invision Gallery index.php album Parameter SQL Injection
29716 Invision Gallery index.php dir Variable Traversal Arbitrary File Disclosure
25231 Invision Gallery post.php album Parameter SQL Injection
20419 Invision Gallery index.php st Parameter SQL Injection
20248 Microsoft IE Embedded Content Processing XSS
17244 Invision Gallery Photo Voting SQL Injection
17243 Invision Gallery editcomment Command comment Parameter SQL Injection
4472 Invision Gallery Module index.php Multiple Parameter SQL Injection

Nessus® Vulnerability Scanner

id Description
2006-10-14 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-925.nasl - Type: ACT_GATHER_INFO
2006-10-14 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-958.nasl - Type: ACT_GATHER_INFO
2005-11-01 Name: The remote web server contains a PHP script that is affected by a SQL injecti...
File: invision_gallery_st_sql_injection.nasl - Type: ACT_ATTACK
2005-06-10 Name: The remote web server contains a PHP application that is vulnerable to multip...
File: invision_gallery_sql_injection.nasl - Type: ACT_ATTACK