header-logo
Suggest Exploit
vendor:
Cycade Gallery
by:
DownFall
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Cycade Gallery
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2012

Cycade Gallery SQL Injection Exploit

An SQL injection vulnerability exists in Cycade Gallery, which allows an attacker to execute arbitrary SQL commands on the underlying database. This can be exploited to gain access to sensitive information, such as usernames and passwords. The vulnerability is due to insufficient sanitization of user-supplied input in the 'g_id' parameter of the 'catalog2.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands.

Mitigation:

Input validation should be used to ensure that user-supplied input is properly sanitized. Additionally, the application should be configured to use the least privileged account with access to the database.
Source

Exploit-DB raw data:

# Exploit Title: Cycade Gallery SQL Injection Exploit
# Date: 3/12/2012
# Author: -DownFall
# Vendor or Software Link: Cycade Content Management - (http://www.cycade.com/)
# Category: Web Apps - (0-Day)
# Google dork: intext:"Powered by Cycade" inurl:"g_id="
# Tested on: Windows 7

http://server/common/catalog2.php?g_id=[SQLi]

Shoutout to all members of Team Intra