6.8
CVSSv2

CVE-2009-4564

Published: 04/01/2010 Updated: 19/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote malicious users to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/.

Vulnerable Product Search on Vulmon Subscribe to Product

zenphoto zenphoto 1.2.5

Exploits

/* * ZenPhoto 125 Completly Blind SQL Injection Exploit * Requirements: magic_quotes = ANY (zenpage disables it anyway), ZenPage needs to be activated and have at least one news category * * What does this exploit let you do: * The precoded functions I provided will allow you to extract the username and password hash of the admin from the d ...