Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:27809
HistoryMar 19, 2012 - 12:00 a.m.

PHP Gift Registry 1.5.5 SQL Injection

2012-03-1900:00:00
vulners.com
34

Exploit Title: PHP Gift Registry 1.5.5 SQL Injection

Date: 02/22/12

Author: G13

Software Link: https://sourceforge.net/projects/phpgiftreg/

Version: 1.5.5

Category: webapps (php)

Vulnerability

The userid parameter in the users.php file is vulnerable to SQL Injection.

A user must be signed in to exploit this.

Vendor Notification

02/22/12 - Vendor Notified
02/24/12 - No response, disclosure

Exploit

http://localhost/phpgiftreg/users.php?action=edit&userid=[SQLi]