packetstormsecurity.org
http://packetstormsecurity.org/1009-exploits/ibphotohost-sql.txt CVE-2010-3601
ibPhotohost 1.1.2 - SQL Injection
Record summary
CVE-2010-3601 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands via the img parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBibPhotohost 1.1.2 - SQL InjectionExploitDB exploitby fred777Not analyzed1 file
References
515070exploit
http://www.exploit-db.com/exploits/15070 43374vdb entry
http://www.securityfocus.com/bid/43374 ADV-2010-2437vdb entry
http://www.vupen.com/english/advisories/2010/2437 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-3601