7.5
CVSSv2

CVE-2008-6648

Published: 07/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote malicious users to execute arbitrary SQL commands via the gid parameter to about_us.php. NOTE: this might be the same issue as CVE-2008-6647.

Vulnerable Product Search on Vulmon Subscribe to Product

ktools photostore 3.4.3

ktools photostore 3.5.2

Exploits

######################################### # Remote SQL Injection Vulnerability # # # # PhotoStore 343 ( galleryphp gid ) # # # ######################################### ## Script NAME : PhotoStore ## VERSION : 343 ## DOWNLOAD : wwwktoolsnet/ ############# ...
\#'#/ (--) -------------------------oOO---(_)---OOo------------------------- | Ktools Photostore <= v352 (crumbsphp) Remote SQL Injection | | (works only with magic quotes = off) | | coded by DNX ...