Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
BID:17536
Info
Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 17536 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2006 12:00AM |
| Updated: | Jun 06 2006 08:02PM |
| Credit: | Qex is credited with the discovery of this vulnerability. |
| Vulnerable: |
Tiny Web Gallery Tiny Web Gallery 1.4 |
| Not Vulnerable: | |
Discussion
Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
Tiny Web Gallery is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 1.4 and prior are vulnerable.
Tiny Web Gallery is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 1.4 and prior are vulnerable.
Exploit / POC
Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
This issue can be exploited through a web client.
An example URI has been provided:
This issue can be exploited through a web client.
An example URI has been provided:
Solution / Fix
Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
Solution:
Version TWG 1.4.2 is available from the vendor; please see the reference section for more information.
Tiny Web Gallery Tiny Web Gallery 1.4
Solution:
Version TWG 1.4.2 is available from the vendor; please see the reference section for more information.
Tiny Web Gallery Tiny Web Gallery 1.4
-
Tiny Web Gallery twg142.zip
http://www.tinywebgallery.com/en/download.htm
References
Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
References:
References: