VendorsInvision Power Servicesinvision_galleryany version
Vulnerabilities

Invision Power Services Invision Gallery any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-5206
SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.
Published 2006-10-09 · Modified
7.51 PoCEPSS 0.043
CVE-2008-0421
SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command.
Published 2008-01-23 · Modified
7.51 PoCEPSS 0.009