info
discussion
exploit
solution
references
All Enthusiast Photopost PHP Pro SQL Injection Vulnerability
No exploit is required to exploit this issue.
The following proof of concept has been provided:
http://www.example.com/directory/showphoto.php?photo=[query]
Privacy Statement
Copyright 2010, SecurityFocus