This is a technical writeup detailing a blind SQL injection vulnerability in iTech StockPhoto Script v2.02. The vulnerability is in the 'stock' POST parameter, which is sent when downloading an image, and the payload demonstrates a boolean-based blind SQLi.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:iTech StockPhoto Script v2.02
No auth needed
Prerequisites:Access to the image download functionality