CVE-2012-0994

Publication date

2012-02-21 00:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.