fGallery 2.4.1 - SQL injection
criticalSQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the album parameter.
- CVSS:
- 9.1
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Jan 30, 2008