Back to Database
Status published
High
CVE-2010-1300
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo...
Vulnerability Description
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbitrary SQL commands via the calbums parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-1300
Credits & Attribution
No credits recorded in the NVD database.
References
- http://packetstormsecurity.org/1003-exploits/yamamah-sql.txt
- http://www.securityfocus.com/bid/39690
- http://osvdb.org/63344
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59404
- http://www.exploit-db.com/exploits/13857
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57415
- http://secunia.com/advisories/39205
- http://www.exploit-db.com/exploits/11947
- http://www.exploit-db.com/exploits/13849
More from yamamah
View All →CVE-2011-3823
Yamamah 1.0 allows remote attackers to obtain sensitive information via...
Medium
5
CVE-2010-2336
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to...
Medium
5
CVE-2010-2335
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00,...
High
7.5
CVE-2010-2334
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00,...
Medium
5
Affected Vendor
yamamah
View all reports →Affected Software
yamamah
Vulnerable Versions:
1.00
Timeline
Official Publish:
April 7th, 2010
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.