CVE-2008-2817
nitro_web_gallery < 1.4.3 - SQL Injection via CatId Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2817. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in NiTrO Web Gallery versions 1.3 to 1.43 via the 'CatId' parameter in 'albums.php'. It allows an attacker to extract user credentials (username, password, email) from the 'tblUsers' table.
Description
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in NiTrO Web Gallery versions 1.3 to 1.43 via the 'CatId' parameter in 'albums.php'. It allows an attacker to extract user credentials (username, password, email) from the 'tblUsers' table.