SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.
https://www.exploit-db.com/exploits/5211
http://www.securityfocus.com/archive/1/489017/100/0/threaded