CVE-2008-0491

SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the album parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fgallery_project:fgallery:2.4.1:*:*:*:*:wordpress:*:*

History

02 Aug 2023, 18:59

Type Values Removed Values Added
CPE cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:fgallery_plugin:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fgallery_project:fgallery:2.4.1:*:*:*:*:wordpress:*:*
References (BID) http://www.securityfocus.com/bid/27464 - Exploit (BID) http://www.securityfocus.com/bid/27464 - Exploit, Third Party Advisory, VDB Entry
References (EXPLOIT-DB) https://www.exploit-db.com/exploits/4993 - (EXPLOIT-DB) https://www.exploit-db.com/exploits/4993 - Third Party Advisory, VDB Entry
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/39964 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/39964 - VDB Entry
References (VUPEN) http://www.vupen.com/english/advisories/2008/0349 - (VUPEN) http://www.vupen.com/english/advisories/2008/0349 - Broken Link
First Time Fgallery Project fgallery
Fgallery Project

Information

Published : 2008-01-30 22:00

Updated : 2024-02-28 11:01


NVD link : CVE-2008-0491

Mitre link : CVE-2008-0491

CVE.ORG link : CVE-2008-0491


JSON object : View

Products Affected

fgallery_project

  • fgallery
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')