|
Bugtraq
mailing list archives
Phpwebgallery <= 1.4.1 SQL injection Vulnerability
From: t4h4 () linuxmail org
Date: 3 Apr 2006 14:07:26 -0000
Moroccan Security Team (|ucif3r)
Greetz To All Freind
Phpwebgallery 1.4.1 is vulnerable to SQL Injection Attacks
The flaw is due to input validation errors in the "category.php" script when handling the "search"variables, which
could be exploited by malicious people to conduct SQL injection attacks.
Exploit:
http://localhost/phpwebgallery/category.php?cat=search&search=[SQL]
t4h4[at]linuxmail[dot]com :D
By Date
By Thread
Current thread:
- Phpwebgallery <= 1.4.1 SQL injection Vulnerability t4h4 (Apr 03)
|