CVE-2008-6790
MindDezign Photo Gallery 2.2 - Unauthenticated Privilege Escalation via Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6790. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit leverages an SQL injection vulnerability in MindDezign Photo Gallery 2.2 to bypass authentication and add an arbitrary administrator account. It uses a crafted SQL query to log in as admin and then sends a POST request to create a new admin user.
Description
The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php.
Exploits (1)
This exploit leverages an SQL injection vulnerability in MindDezign Photo Gallery 2.2 to bypass authentication and add an arbitrary administrator account. It uses a crafted SQL query to log in as admin and then sends a POST request to create a new admin user.