28447Third-party advisory
http://secunia.com/advisories/28447 CVE-2008-0256
ASP Photo Gallery 1.0 - Multiple SQL Injections
Record summary
CVE-2008-0256 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBASP Photo Gallery 1.0 - Multiple SQL InjectionsExploitDB exploitby trewNot analyzed1 file
References
527262vdb entry
http://www.securityfocus.com/bid/27262 aspphotogallery-multiple-sql-injection(39646)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39646 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-0256 4900exploit
https://www.exploit-db.com/exploits/4900