CVE-2007-1469
Absolute Image Gallery 2.0 - SQL Injection via categoryid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1469. PoCs published by WiLdBoY.
AI-analyzed exploit summary This exploit demonstrates SQL injection in Absolute Image Gallery 2.0 via the 'categoryid' parameter, allowing command execution through MSSQL stored procedures like 'xp_cmdshell'. It includes examples for file operations and code injection.
Description
SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
Exploits (1)
This exploit demonstrates SQL injection in Absolute Image Gallery 2.0 via the 'categoryid' parameter, allowing command execution through MSSQL stored procedures like 'xp_cmdshell'. It includes examples for file operations and code injection.