The WordPress Photo Gallery module suffers from a remote SQL injection vulnerability.

[Via - http://packetstormsecurity.org/filedesc/wpgallery-sql.txt.html]