Singapore Image Gallery Remote File Include And Cross Site Scripting Vulnerabilities
BID:65420
Info
Singapore Image Gallery Remote File Include And Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 65420 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2014 12:00AM |
| Updated: | Feb 05 2014 12:00AM |
| Credit: | TUNISIAN CYBER |
| Vulnerable: |
singapore singapre 0.9.10 singapore singapore 0.9.9 b beta |
| Not Vulnerable: | |
Discussion
Singapore Image Gallery Remote File Include And Cross Site Scripting Vulnerabilities
Singapore Image Gallery is prone to a remote file-include vulnerability and a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to obtain potentially sensitive information, execute arbitrary script code in the context of the web server process, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or steal cookie-based authentication credentials and launch other attacks.
Singapore 0.9.9b and 0.9.10 are vulnerable; other versions may also be vulnerable.
Singapore Image Gallery is prone to a remote file-include vulnerability and a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to obtain potentially sensitive information, execute arbitrary script code in the context of the web server process, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or steal cookie-based authentication credentials and launch other attacks.
Singapore 0.9.9b and 0.9.10 are vulnerable; other versions may also be vulnerable.
Solution / Fix
Singapore Image Gallery Remote File Include And Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
Singapore Image Gallery Remote File Include And Cross Site Scripting Vulnerabilities
References:
References:
- singapore Homepage (singapore)