Description
|
|
Multiple vulnerabilities have been identified in Graugon Gallery, which could be exploited by remote attackers to bypass security restrictions, or inject arbitrary SQL queries and scripting code.
The first issue is caused by input validation errors in the "view.php" scripts when processing the "id" parameter, which could be exploited to conduct SQL injection and cross site scripting attacks.
The second vulnerability is caused by a design error in the "admin.php" script when handling administrative cookies, which could be exploited to gain unauthorized administrative access.
|