Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15241
HistoryNov 28, 2006 - 12:00 a.m.

uPhotoGallery (v 1.1) SQL Injection

2006-11-2800:00:00
vulners.com
15

#Aria-Security Team Advisory
#<www.Aria-security.Com For English >
#<www.Aria-Security.net For Persian >
#-----------------------------------------------------------
#Software: uPhotoGallery 1.1
#Method: SQL injection

#PoC:
#http://target/slideshow.asp?img_id=290&amp;ci=[SQL Injection]
#http://target/thumbnails.asp?ci=[SQL Injection]

#Contact: [email protected]