7.5
CVSSv2

CVE-2008-4335

Published: 30/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote malicious users to execute arbitrary SQL commands via the apa_album_ID parameter.

Affected Products

Vendor Product Versions
Atomic Photo AlbumAtomic Photo Album1.1.0 Pre4

Exploits

<?php ini_set("max_execution_time",0); print_r(' ############################################################### # # Atomic Photo Album 110pre4 - Blind SQL Injection Exploit # # Vulnerability discovered by: Stack # Exploit coded by: Stack # Greetz ...
[~]----------------------------------------------------------------------- [~] Atomic Photo Album 110pre4 [albumphp] - Multiple Remote Vulnerabilities [~] [~] atomicpasourceforgenet [~] ---------------------------------------------------------- [~] Bug founded by d3v1l [~] [~] Date: 25092008 [~] [~] [~] d3v1l@spoofercom [~] [~] ----- ...