vendor:
ZenPhoto
by:
SecurityFocus
7,5
CVSS
HIGH
SQL Injection and Path Disclosure
89, 522
CWE
Product Name: ZenPhoto
Affected Version From: ZenPhoto 1.4.4
Affected Version To: ZenPhoto 1.4.4
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
ZenPhoto Multiple Vulnerabilities
ZenPhoto is prone to an SQL-injection vulnerability and multiple path-disclosure vulnerabilities. A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. The attacker may gain access to potentially sensitive information that can aid in other attacks.
Mitigation:
Input validation should be used to prevent SQL injection attacks. Path disclosure vulnerabilities can be mitigated by removing the vulnerable code or by disabling directory listing.