7.5
CVSSv2

CVE-2005-1629

Published: 17/05/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in member.php for Photopost PHP Pro allows remote malicious users to execute arbitrary SQL commands via the verifykey parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

photopost photopost php pro 3.1

photopost photopost php pro 3.2

photopost photopost php pro 5.0_rc3

photopost photopost php pro 4.0

photopost photopost php pro 4.6

photopost photopost php pro 3.3

photopost photopost php pro 4.1

photopost photopost php pro 4.8.1

Exploits

#!/usr/bin/perl # PhotoPost Arbitrary Data Exploit # -------------------------------- # INFPG - Hacking&Security Research # # # Use first the exploit code,then You'll get admin MD5 hash and user name on your mail # # Greats: Infam0us Gr0up team/crew/fans,Zone-H,securiteam,str0ke-milw0rm,addict3d, # Thomas-secunia,Yudha,Dcrab's,Kavling Communit ...