#Aria-Security Team Advisory # # #----------------------------------------------------------- #Software: uPhotoGallery 1.1 #Method: SQL injection # #PoC: #http://target/slideshow.asp?img_id=290&ci=[SQL Injection] #http://target/thumbnails.asp?ci=[SQL Injection] # #Contact: Advisory@aria-security.net