Total vulnerabilities in the database
SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.
Software | From | Fixed in |
---|---|---|
invision_power_services / invision_gallery | - | 2.0.7.x |
invision_power_services / invision_gallery | 2.0.3 | 2.0.3.x |
invision_power_services / invision_gallery | 1.0.1 | 1.0.1.x |
invision_power_services / invision_gallery | 1.3 | 1.3.x |
invision_power_services / invision_gallery | 1.3.1 | 1.3.1.x |
invision_power_services / invision_gallery | 2.0.6 | 2.0.6.x |