PHPgraphy Script Injection Vulnerability
BID:14669
Info
PHPgraphy Script Injection Vulnerability
| Bugtraq ID: | 14669 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2005 12:00AM |
| Updated: | Aug 26 2005 12:00AM |
| Credit: | Cedric Cochin is credited with the discovery of this vulnerability. |
| Vulnerable: |
phpGraphy phpGraphy 0.9.9 a |
| Not Vulnerable: |
phpGraphy phpGraphy 0.9 .10 |
Discussion
PHPgraphy Script Injection Vulnerability
phpGraphy is prone to a script injection vulnerability. This is due to a lack of proper sanitization of user-supplied input.
A malicious user may cause arbitrary script code to be executed in the Web browser context of an unsuspecting victim. This may lead to the theft of cookie-based authentication credentials in the context of the victim's browser application.
Further attacks are also possible.
phpGraphy is prone to a script injection vulnerability. This is due to a lack of proper sanitization of user-supplied input.
A malicious user may cause arbitrary script code to be executed in the Web browser context of an unsuspecting victim. This may lead to the theft of cookie-based authentication credentials in the context of the victim's browser application.
Further attacks are also possible.
Exploit / POC
PHPgraphy Script Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHPgraphy Script Injection Vulnerability
Solution:
The vendor has released version 0.9.10 to address this issue.
phpGraphy phpGraphy 0.9.9 a
Solution:
The vendor has released version 0.9.10 to address this issue.
phpGraphy phpGraphy 0.9.9 a
-
phpGraphy phpgraphy-0.9.10.tar.gz
http://prdownloads.sourceforge.net/phpgraphy/phpgraphy-0.9.10.tar.gz
References
PHPgraphy Script Injection Vulnerability
References:
References:
- Multiple PHP Images Galleries EXIF Metadata XSS Vulnerabilities (Cedric Cochin)