TCW PHP Album 'album' Parameter Input Validation Vulnerability
BID:41382
Info
TCW PHP Album 'album' Parameter Input Validation Vulnerability
| Bugtraq ID: | 41382 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2714 CVE-2010-2715 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | L0rd CrusAd3r |
| Vulnerable: |
The TCW Organization TCW PHP Album 0 |
| Not Vulnerable: | |
Discussion
TCW PHP Album 'album' Parameter Input Validation Vulnerability
TCW PHP Album is prone to an input validation vulnerability that may allow an attacker to perform cross-site scripting, SQL-injection, and HTML-Injection attacks because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application, access or modify data, run HTML or JavaScript code in the context of the affected site, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit latent vulnerabilities in the underlying database; other attacks are also possible.
TCW PHP Album 1.0 is vulnerable; other versions may be affected.
TCW PHP Album is prone to an input validation vulnerability that may allow an attacker to perform cross-site scripting, SQL-injection, and HTML-Injection attacks because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application, access or modify data, run HTML or JavaScript code in the context of the affected site, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit latent vulnerabilities in the underlying database; other attacks are also possible.
TCW PHP Album 1.0 is vulnerable; other versions may be affected.
Exploit / POC
TCW PHP Album 'album' Parameter Input Validation Vulnerability
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/photos/index.php?album=[sqli]
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/photos/index.php?album=[sqli]
Solution / Fix
TCW PHP Album 'album' Parameter Input Validation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TCW PHP Album 'album' Parameter Input Validation Vulnerability
References:
References:
- TCW PHP Album - Homepage (The TCW Organization)