Description
XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through the photo_id parameter. Attackers can send GET requests to photo.php with malicious photo_id values to extract sensitive data, bypass authentication, or modify database contents.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Ahmet Ümit BAYRAM
References
www.exploit-db.com/exploits/46609 (ExploitDB-46609)
www.vulncheck.com/...t-multiple-sql-injections-via-photo-php (VulnCheck Advisory: XooGallery Lastest Latest Multiple SQL Injections via photo.php)