PhotoPost Script Injection Vulnerability
BID:14671
Info
PhotoPost Script Injection Vulnerability
| Bugtraq ID: | 14671 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2005 12:00AM |
| Updated: | Aug 26 2005 12:00AM |
| Credit: | Cedric Cochin is credited with the discovery of this vulnerability. |
| Vulnerable: |
PhotoPost PhotoPost Pro 5.1 PhotoPost PhotoPost Pro |
| Not Vulnerable: | |
Discussion
PhotoPost Script Injection Vulnerability
PhotoPost is prone to a script injection vulnerability. This is due to a lack of proper sanitization of user-supplied input.
A malicious user may cause arbitrary script code to be executed in the Web browser context of an unsuspecting victim. This may lead to the theft of cookie-based authentication credentials in the context of the victim's browser application.
Further attacks are also possible.
PhotoPost is prone to a script injection vulnerability. This is due to a lack of proper sanitization of user-supplied input.
A malicious user may cause arbitrary script code to be executed in the Web browser context of an unsuspecting victim. This may lead to the theft of cookie-based authentication credentials in the context of the victim's browser application.
Further attacks are also possible.
Exploit / POC
PhotoPost Script Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PhotoPost Script Injection Vulnerability
Solution:
No exploit is required.
Solution:
No exploit is required.
References
PhotoPost Script Injection Vulnerability
References:
References:
- Multiple PHP Images Galleries EXIF Metadata XSS Vulnerabilities (Cedric Cochin)
- PhotoPost Pro Homepage (PhotoPost)