CVE-2016-4337 | Ktools.net PhotoStore up to 4.7.4 mgr.login.php email sql injection (EDB-40046)
A vulnerability classified as critical has been found in Ktools.net PhotoStore up to 4.7.4. Affected is an unknown function of the file mgr.login.php. The manipulation of the argument email leads to sql injection.
This vulnerability is traded as CVE-2016-4337. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.