Description
Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gallery_id parameter. Attackers can send GET requests to gallery.php with malicious gallery_id values using UNION-based SQL injection to extract sensitive database information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Ahmet Ümit BAYRAM
References
www.exploit-db.com/exploits/46597 (ExploitDB-46597)
www.vulncheck.com/...cripti-v1-sql-injection-via-gallery-php (VulnCheck Advisory: Jettweb PHP Hazir Haber Sitesi Scripti V1 SQL Injection via gallery.php)