CVE-2008-2817
23.06.2008, 17:41
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.
Vendor | Product | Version |
---|---|---|
nitropowered | nitro_web_gallery | 𝑥 ≤ 1.4.3 |
𝑥
= Vulnerable software versions