Back to Database
Status published
High
CVE-2010-2335
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00,...
Vulnerability Description
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to execute arbitrary SQL commands via the news parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-2335
Credits & Attribution
No credits recorded in the NVD database.
More from yamamah
View All →CVE-2011-3823
Yamamah 1.0 allows remote attackers to obtain sensitive information via...
Medium
5
CVE-2010-2336
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to...
Medium
5
CVE-2010-2334
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00,...
Medium
5
CVE-2010-1300
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo...
High
7.5
Affected Vendor
yamamah
View all reports →Affected Software
yamamah
Vulnerable Versions:
1.00
Timeline
Official Publish:
June 18th, 2010
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.