CVE-2006-5206: SQL Injection
SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5206?
CVE-2006-5206 is classified as a medium severity SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2006-5206?
To fix CVE-2006-5206, upgrade Invision Gallery to a version greater than 2.0.7 where the vulnerability is patched.
Which versions of Invision Gallery are affected by CVE-2006-5206?
CVE-2006-5206 affects Invision Gallery versions up to and including 2.0.7, as well as earlier versions like 1.0.1, 1.3, and 1.3.1.
What type of attack can exploit CVE-2006-5206?
CVE-2006-5206 can be exploited by a remote SQL injection attack through manipulation of the album parameter in specific PHP scripts.
Can CVE-2006-5206 impact website integrity?
Yes, successful exploitation of CVE-2006-5206 can lead to unauthorized data access and manipulation, compromising website integrity.