Description
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.
Remediation
References
Related Vulnerabilities
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2025-43795)
MediaWiki Uncontrolled Resource Consumption Vulnerability (CVE-2021-46149)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9048)
Apache Traffic Server Stack-based Buffer Overflow Vulnerability (CVE-2026-58181)
Oracle Database Server Improper Privilege Management Vulnerability (CVE-2026-60175)