CVE-2008-6648
Ktools PhotoStore 3.4.3 and 3.5.2 - SQL Injection via gid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6648. PoCs published by DNX.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Ktools Photostore <= v3.5.2 via the 'gid' parameter in 'crumbs.php' and the 'id' parameter in 'image_details_editor.php'. It includes functional PoC URLs that extract user credentials from the database when magic quotes are disabled.
Description
SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter to about_us.php. NOTE: this might be the same issue as CVE-2008-6647.
Exploits (2)
The exploit demonstrates SQL injection vulnerabilities in Ktools Photostore <= v3.5.2 via the 'gid' parameter in 'crumbs.php' and the 'id' parameter in 'image_details_editor.php'. It includes functional PoC URLs that extract user credentials from the database when magic quotes are disabled.
This exploit demonstrates a SQL injection vulnerability in PhotoStore 3.4.3 via the 'gid' parameter in gallery.php. It includes payloads to extract admin and user credentials from the database.