* Technical Description *
A new vulnerability was identified in Zomm Media Gallery, which may be exploited by attackers to execute arbitrary SQL commands. The flaw is due to an input validation error in the "index.php" script when handling a specially crafted "catid" parameter, which may be exploited by attackers to execute arbitrary SQL commands.
* Affected Products *
Zomm Media Gallery version 2.1.2 and prior
* Solution *
The FrSIRT is not aware of any official supplied patch for this issue.
* References *
http://www.frsirt.com/english/advisories/2005/0330
* Credits *
Vulnerability reported by Andreas Constantinides
* ChangeLog *
seen at:
www.k-otik.com