cpe:/a:nitropowered:nitro_web_gallery:1.4.3 CVE-2008-2817 2008-06-23T13:41:00.000-04:00 2017-09-28T21:31:20.727-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2008-06-23T14:26:00.000-04:00 ALLOWS_OTHER_ACCESS BID 29753 EXPLOIT-DB 5830 XF nitro-albums-sql-injection(43100) SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.