Security Advisory
CVE-2012-0994
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.