Security Advisory
CVE-2008-4912
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.