The provided text describes an SQL injection vulnerability in ZenPhoto 1.4.4, where the 'date' parameter in the search functionality is vulnerable. It also mentions path-disclosure vulnerabilities but lacks technical depth or exploit code.
Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target:ZenPhoto 1.4.4
No auth needed
Prerequisites:Access to the target ZenPhoto instance