CVE-2008-6649
07.04.2009, 14:17
SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Vendor | Product | Version |
---|---|---|
ktools | photostore | 2.5 |
ktools | photostore | 2.9.8 |
ktools | photostore | 3.1.0 |
ktools | photostore | 3.1.1 |
ktools | photostore | 3.2 |
ktools | photostore | 3.2.1 |
ktools | photostore | 3.4 |
ktools | photostore | 3.4.2 |
ktools | photostore | 3.4.3 |
ktools | photostore | 3.5 |
ktools | photostore | 3.5.1 |
ktools | photostore | 3.5.2 |
𝑥
= Vulnerable software versions
References