CVE-2008-0421 – Invision Gallery 2.0.7 - SQL Injection
https://notcve.org/view.php?id=CVE-2008-0421
SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command. Vulnerabilidad de inyección SQL en Invision Gallery 2.0.7 y anteriores permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro album en un comando rate. • https://www.exploit-db.com/exploits/4966 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2006-5205 – Invision Gallery 2.0.7 - 'readfile()' / SQL Injection
https://notcve.org/view.php?id=CVE-2006-5205
Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used. Vulnerabilidad de escalada de directorio en Invision Gallery 2.0.7 permite a atacantes remotos leer archivos de su elección mediante una secuencia .. (punto punto) en el parámetro dir en (1) index.php y (2) forum/index.php, cuando se usa el comando viewimage en el módulo de galería. • https://www.exploit-db.com/exploits/2473 http://secunia.com/advisories/22400 http://www.securityfocus.com/bid/20328 https://exchange.xforce.ibmcloud.com/vulnerabilities/29334 •
CVE-2006-5206 – Invision Gallery 2.0.7 - 'readfile()' / SQL Injection
https://notcve.org/view.php?id=CVE-2006-5206
SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used. Vulnerabilidad de inyección SQL en Invision Gallery 2.0.7 permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro album en (2) index.php y (2) forum/index.php, cuando se usa el comando rate en el automódulo galería. • https://www.exploit-db.com/exploits/2473 http://secunia.com/advisories/22400 http://www.securityfocus.com/bid/20327 https://exchange.xforce.ibmcloud.com/vulnerabilities/29333 •
CVE-2005-1948 – Invision Power Services Invision Gallery 1.0.1/1.3 - SQL Injection
https://notcve.org/view.php?id=CVE-2005-1948
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo. • https://www.exploit-db.com/exploits/25806 http://marc.info/?l=bugtraq&m=111834146710329&w=2 http://www.gulftech.org/?node=research&article_id=00079-06092005 http://www.securityfocus.com/bid/13907 •
CVE-2004-1835 – Invision Power Services Invision Gallery 1.0.1 - Multiple SQL Injections
https://notcve.org/view.php?id=CVE-2004-1835
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters. Invision Gallery version 1.0.1 suffers from multiple remote SQL injection vulnerabilities. • https://www.exploit-db.com/exploits/23867 https://www.exploit-db.com/exploits/43807 http://marc.info/?l=bugtraq&m=107997906500032&w=2 http://secunia.com/advisories/11194 http://securitytracker.com/id?1009512 http://www.osvdb.org/4472 http://www.securityfocus.com/bid/9944 https://exchange.xforce.ibmcloud.com/vulnerabilities/15566 •