CVE-2006-6370: SQL Injection
SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and possibly have other impacts, as demonstrated using a "SELECT BENCHMARK" statement in the img parameter in a doaddcomment operation in index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6370?
CVE-2006-6370 is classified as a moderate severity SQL injection vulnerability that can lead to denial of service.
How do I fix CVE-2006-6370?
To fix CVE-2006-6370, upgrade to Invision Gallery version 2.0.8 or later where the vulnerability has been patched.
What software is affected by CVE-2006-6370?
CVE-2006-6370 affects Invision Gallery version 2.0.7.
What type of vulnerability is CVE-2006-6370?
CVE-2006-6370 is an SQL injection vulnerability that can be exploited via crafted input to the img parameter.
What are the potential impacts of CVE-2006-6370?
Exploitation of CVE-2006-6370 can lead to denial of service and potentially other attacks on the Invision Gallery.