packetstormsecurity.com
http://packetstormsecurity.com/files/137734/Ktools-Photostore-4.7.5-Blind-SQL-Injection.html CVE-2016-4337
CRITICAL
Ktools Photostore 4.7.5 - Blind SQL Injection
Record summary
CVE-2016-4337 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBKtools Photostore 4.7.5 - Blind SQL InjectionExploitDB exploitby Gal Goldshtein & Viktor MininNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-4337 40046exploit
https://www.exploit-db.com/exploits/40046