Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11849
HistoryMar 19, 2006 - 12:00 a.m.

SQL-injection and XSS in photokorn gallery

2006-03-1900:00:00
vulners.com
8

Advisory: SQL-injection and XSS in photokorn gallery

Home Page: http://www.telekorn.com

Уязвимость/Vulnerability:
SQL-injection

Уязвимый скрипт/Vulnerable script: search.php

http://www.stockvault.net/gallery/search.php?action=search&type=detail&where[]=keywords'&keyword=dotted

Раскрытие установочного пути/Exposure of installation path:

Уязвимый скрипт/Vulnerable script:index.php, download.php

http://www.stockvault.net/gallery/index.php?action=showpic&cat=64&pic=3304'

http://www.stockvault.net/gallery/index.php?action=showgal&cat=39'

http://www.stockvault.net/gallery/index.php?action=showpic&cat=34&pic=1'

http://www.stockvault.net/gallery/download.php?cat=34&pic=1'


Cyber Lords Team
www.cyberlords.net