Amateur Photographer's Image Gallery Multiple Security Vulnerabilities
BID:56110
Info
Amateur Photographer's Image Gallery Multiple Security Vulnerabilities
| Bugtraq ID: | 56110 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2012 12:00AM |
| Updated: | Oct 18 2012 12:00AM |
| Credit: | cr4wl3r |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Amateur Photographer's Image Gallery Multiple Security Vulnerabilities
Amateur Photographer's Image Gallery is prone to multiple SQL injection vulnerabilities, a cross-site scripting vulnerability, and an arbitrary file-disclosure vulnerability because the application fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, and obtain sensitive information from local files on computers running the vulnerable application.
Amateur Photographer's Image Gallery 0.9a is vulnerable; other versions may also be affected.
Amateur Photographer's Image Gallery is prone to multiple SQL injection vulnerabilities, a cross-site scripting vulnerability, and an arbitrary file-disclosure vulnerability because the application fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, and obtain sensitive information from local files on computers running the vulnerable application.
Amateur Photographer's Image Gallery 0.9a is vulnerable; other versions may also be affected.
Exploit / POC
Amateur Photographer's Image Gallery Multiple Security Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/path_gallery/force-download.php?file=[RFD]
http://www.example.com/path_gallery/plist.php?albumid=[SQLi]
http://www.example.com/path_gallery/plist.php?albumid=[XSS]
http://www.example.com/path_gallery/fullscreen.php?albumid=[SQLi]
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/path_gallery/force-download.php?file=[RFD]
http://www.example.com/path_gallery/plist.php?albumid=[SQLi]
http://www.example.com/path_gallery/plist.php?albumid=[XSS]
http://www.example.com/path_gallery/fullscreen.php?albumid=[SQLi]
Solution / Fix
Amateur Photographer's Image Gallery Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Amateur Photographer's Image Gallery Multiple Security Vulnerabilities
References:
References: