PHPImageView Cross Site Scripting Vulnerability
BID:4668
Info
PHPImageView Cross Site Scripting Vulnerability
| Bugtraq ID: | 4668 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 04 2002 12:00AM |
| Updated: | May 04 2002 12:00AM |
| Credit: | Posted to BugTraq May 5, 2002 by frog frog <[email protected]>. |
| Vulnerable: |
onlinetools.org PHPImageView 1.0 |
| Not Vulnerable: | |
Discussion
PHPImageView Cross Site Scripting Vulnerability
PHPImageView 1.0 is a simple image display system. It is vulnerable to cross site scripting whereby a user supplied variable is returned as the content of an error message, allowing script submitted as a URL to be interpreted by the browser.
In addition to this, phpinfo() can be invoked - revealing a detailed summary of operating system setup including file system structure and version information.
PHPImageView 1.0 is a simple image display system. It is vulnerable to cross site scripting whereby a user supplied variable is returned as the content of an error message, allowing script submitted as a URL to be interpreted by the browser.
In addition to this, phpinfo() can be invoked - revealing a detailed summary of operating system setup including file system structure and version information.
Exploit / POC
PHPImageView Cross Site Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHPImageView Cross Site Scripting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.