CVE-2008-6649
Ktools PhotoStore <= 3.5.2 - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6649. PoCs published by DNX, Mr.SQL.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Ktools Photostore <= v3.5.2 via the 'gid' parameter in 'crumbs.php' and the 'id' parameter in 'image_details_editor.php'. It includes functional PoC URLs that extract user credentials from the database when magic quotes are disabled.
Description
SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (2)
The exploit demonstrates SQL injection vulnerabilities in Ktools Photostore <= v3.5.2 via the 'gid' parameter in 'crumbs.php' and the 'id' parameter in 'image_details_editor.php'. It includes functional PoC URLs that extract user credentials from the database when magic quotes are disabled.
This exploit demonstrates a SQL injection vulnerability in PhotoStore 3.4.3 via the 'gid' parameter in gallery.php. It allows an attacker to extract admin and user credentials from the database without authentication.