vendor:
Picture Rating 1.0
by:
t0pP8uZz
7.5
CVSS
HIGH
Blind SQL Injection
CWE
Product Name: Picture Rating 1.0
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
Picture Rating 1.0 Blind SQL Injection Exploit
This exploit allows an attacker to perform a blind SQL injection attack on the target host running the Picture Rating 1.0 script. After running the exploit, the attacker will gain access to the admin details, allowing them to log in to the admin area. From there, they can upload a shell, edit settings to allow PHP extensions, and upload a shell. By navigating to the uploaded shell's link, the attacker gains control.
Mitigation:
The vendor was not notified about this vulnerability. Users should consider upgrading to a newer, more secure version of the software or finding an alternative solution.