SQL injection vulnerability in Webmatic before 2.6.2, and possibly other versions before 2.7, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly related to admin/admin_album.php and admin/admin_downloads.php. NOTE: some of these details are obtained from third party information.
Link | Tags |
---|---|
http://secunia.com/advisories/26019 | third party advisory |
http://www.securityfocus.com/bid/24878 | vdb entry |
http://osvdb.org/41104 | vdb entry |
http://www.valarsoft.com/index.php?page=home¬izie=¬ID=144#npos144 | patch |
http://www.vupen.com/english/advisories/2007/2465 | vdb entry |