CVE-2008-5641

critical

Description

SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

References

https://www.exploit-db.com/exploits/7299

http://www.vupen.com/english/advisories/2008/3297

http://securityreason.com/securityalert/4767

http://secunia.com/advisories/32901

Details

Source: Mitre, NVD

Published: 2008-12-17

Updated: 2026-04-23

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00169