CVE-2005-0805
N/A
N/A
Summary
SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via certain parameters that are used as global variables, as demonstrated using the imageid parameter, which is not properly handled by imagegallery.php.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://marc.info/?l=bugtraq&m=111116479910230&w=2
- http://www.subdreamer.com/forum/showthread.php?t=2501
- http://www.securityfocus.com/archive/1/437983/100/200/threaded
- http://www.securityfocus.com/bid/12839
References
- http://marc.info/?l=bugtraq&m=111116479910230&w=2
- http://www.subdreamer.com/forum/showthread.php?t=2501
- http://www.securityfocus.com/archive/1/437983/100/200/threaded
- http://www.securityfocus.com/bid/12839
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.