mcGallery PRO Multiple Input Validation Vulnerabilities

No exploit is required.

Example URI have been provided:

http://www.example.com/index.php?language=../FILE

http://www.example.com/show.php?start=0&id=[SQL]
http://www.example.com/show.php?start=[SQL]
http://www.example.com/index.php?album=[SQL]
http://www.example.com/show.php?rand=1&id=[SQL]
http://www.example.com/show.php?rand=[SQL]


 

Privacy Statement
Copyright 2010, SecurityFocus