SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the editcomment parameter, a different version and vector than CVE-2006-2862.
https://www.exploit-db.com/exploits/4019
http://www.vupen.com/english/advisories/2007/2044