Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Softbiz Image Gallery Multiple SQL Injection Vulnerabilities

These issues can be exploited through a web client.

Example URIs have been provided:

http://www.example.com/imagegallery/image_desc.php?id=[SQL]

http://www.example.com/imagegallery/template.php?provided=[SQL]

http://www.example.com/imagegallery/suggest_image.php?cid=[SQL]

http://www.example.com/imagegallery/insert_rating.php?img_id=[sql]

http://www.example.com/imagegallery/images.php?cid=[SQL]







 

Privacy Statement
Copyright 2009, SecurityFocus