[] NeoSense

PhotoPost - PHP SQL Injection

Author: Cyber-sec
type: webapps
platform: php
port: 
date_added: 2010-07-23 
date_updated: 2010-07-23 
verified: 0 
codes: OSVDB-12735 
tags: 
aliases:  
screenshot_url:  
application_url: 

# Exploit Title: PhotoPost PHP SQL Injection Vulnerability
# Date: 23/07/2010
# Author: Cyber-sec
# Software Link: www.photopost.com
# Version: 4.0 - 4.6
# Tested on: windows xp pack 3
# CVE : N/A

--------------------------exploit------------------------------
dork : Powered by: PhotoPost PHP 4.6

exploit: www.site.com/photopost/index.php?cat=1 [sql injection]
---------------------------------------------------------------------------------------
Special Thanks to : Dz-Ghost theblind747 all my frend