SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
| Software | From | Fixed in |
|---|---|---|
| exv2 / bamagalerie | 3.041 | 3.041.x |
| exv2 / exv2 | 2.0.6 | 2.0.6.x |
| exv2 / bamagalerie | 3.03 | 3.03.x |