Description
VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
[Edd13Mora]
References
www.exploit-db.com/exploits/51033 (ExploitDB-51033)
www.viaviweb.com (Vendor Homepage)
www.vulncheck.com/...n-sql-injection-via-editgalleryimagephp (VulnCheck Advisory: VIAVIWEB Wallpaper Admin 1.0 SQL Injection via edit_gallery_image.php)