Gallarific Cross Site Scripting and Authentication Bypass Vulnerabilities
BID:28163
Info
Gallarific Cross Site Scripting and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 28163 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1327 CVE-2008-1326 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | ZoRLu is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Gallarific Gallarific paid version Gallarific Gallarific free version |
| Not Vulnerable: |
Gallarific Gallarific 2.1 free version Gallarific Gallarific 2.0 paid version |
Discussion
Gallarific Cross Site Scripting and Authentication Bypass Vulnerabilities
Gallarific is prone to a cross-site scripting vulnerability and multiple authentication-bypass vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, add new categories, add new users, and modify existing users. Other attacks are also possible.
These issues affect both the commercial and the free versions of Gallarific.
Gallarific is prone to a cross-site scripting vulnerability and multiple authentication-bypass vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, add new categories, add new users, and modify existing users. Other attacks are also possible.
These issues affect both the commercial and the free versions of Gallarific.
Exploit / POC
Gallarific Cross Site Scripting and Authentication Bypass Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim into following a malicious URI.
The following proof-of-concept URIs are available:
http://www.example.com/gadmin/gallery.php?task=delete&id=1
http://www.example.com/gadmin/gallery.php?task=edit&id=1
The following examples and exploit are also available:
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim into following a malicious URI.
The following proof-of-concept URIs are available:
http://www.example.com/gadmin/gallery.php?task=delete&id=1
http://www.example.com/gadmin/gallery.php?task=edit&id=1
The following examples and exploit are also available:
Solution / Fix
Gallarific Cross Site Scripting and Authentication Bypass Vulnerabilities
Solution:
Updates are available. Please contact the vendor for details.
Solution:
Updates are available. Please contact the vendor for details.
References
Gallarific Cross Site Scripting and Authentication Bypass Vulnerabilities
References:
References:
- Gallarific Homepage (Gallarific)