vendor:
PhpWebGallery
by:
ka0x
7.5
CVSS
HIGH
Blind SQL Injection
CWE
Product Name: PhpWebGallery
Affected Version From: 1.3.2004
Affected Version To: 1.3.2004
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
PhpWebGallery 1.3.4 Blind SQL Injection Exploit
This exploit targets a blind SQL injection vulnerability in PhpWebGallery version 1.3.4. By exploiting this vulnerability, an attacker can extract sensitive information from the database. The exploit uses a brute force technique to guess the characters in the database.
Mitigation:
Update to a patched version of PhpWebGallery to prevent the exploitation of this vulnerability. Additionally, ensure that user input is properly sanitized and validated to prevent SQL injection attacks.