Zenphoto Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2012-0994 - Vulnerability Database

Zenphoto Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2012-0994

Medium
Reference: CVE-2012-0994
Title: Zenphoto Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.