ASP Photo Gallery Multiple SQL Injection

Application: ASP Photo Gallery
Affected Version: 1.0.
Vendor’s URL: http://www.matteobinda.com/apg.php
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitized.