CVE-2008-6648

Ktools Photostore - SQL Injection

Title source: rule

Description

SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter to about_us.php. NOTE: this might be the same issue as CVE-2008-6647.

Exploits (2)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/5580
exploitdb WORKING POC VERIFIED
by DNX · textwebappsphp
https://www.exploit-db.com/exploits/5582

Scores

EPSS 0.0055
EPSS Percentile 67.7%

Classification

CWE
CWE-89
Status draft

Affected Products (2)

ktools/photostore
ktools/photostore

Timeline

Published Apr 07, 2009
Tracked Since Feb 18, 2026