Full title: Amateur Photographer 's Image Gallery 0.9a XSS / SQL Injection Category: web applications Platform: php Amateur Photographer's Image Gallery version 0.9a suffers from cross site scripting, remote file disclosure, and remote SQL injection vulnerabilities. # 0day.today @ http://0day.today/