CVE-2008-6647
Ktools PhotoStore 3.4.3 - SQL Injection via Gallery gid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6647. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PhotoStore 3.4.3 via the 'gid' parameter in gallery.php. It allows an attacker to extract admin and user credentials from the database without authentication.
Description
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL commands via the gid parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in PhotoStore 3.4.3 via the 'gid' parameter in gallery.php. It allows an attacker to extract admin and user credentials from the database without authentication.
The exploit demonstrates SQL injection vulnerabilities in Ktools Photostore <= v3.5.2 via the 'crumbs.php' and 'image_details_editor.php' scripts. It includes functional PoC URLs that extract user credentials from the database when magic quotes are disabled.