Total vulnerabilities in the database
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.
CVSS v2:
No CWE or OWASP classifications available.