John Beatty Easy PHP Photo Album dir Parameter HTML Injection Vulnerability
BID:8977
Info
John Beatty Easy PHP Photo Album dir Parameter HTML Injection Vulnerability
| Bugtraq ID: | 8977 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2003 12:00AM |
| Updated: | Nov 04 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to nimber <[email protected]>. |
| Vulnerable: |
John Beatty Easy PHP Photo Album 1.0 |
| Not Vulnerable: | |
Discussion
John Beatty Easy PHP Photo Album dir Parameter HTML Injection Vulnerability
It has been reported that Easy PHP Photo Album is prone to a HTML injection vulnerability that may allow an attacker to execute HTML code in a user's browser. The issue is reported to be present in the 'dir' parameter. This problem is due to insufficient sanitization of user-supplied input.
Successful exploitation of this vulnerability may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Easy PHP Photo Album version 1.0 has been reported to be vulnerable to this issue, however prior versions may be affected as well.
It has been reported that Easy PHP Photo Album is prone to a HTML injection vulnerability that may allow an attacker to execute HTML code in a user's browser. The issue is reported to be present in the 'dir' parameter. This problem is due to insufficient sanitization of user-supplied input.
Successful exploitation of this vulnerability may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Easy PHP Photo Album version 1.0 has been reported to be vulnerable to this issue, however prior versions may be affected as well.
Exploit / POC
John Beatty Easy PHP Photo Album dir Parameter HTML Injection Vulnerability
The following proof of concept has been provided:
http://www.example.com/photos/showimages.php?dir=<iframe%20src="C:\"%20width=400%20height=400></iframe>
http://www.example.com//photos/showfullimage.php?dir=[dir name][spc]St[spc]Clair&image=<h1>hello</h1>
The following proof of concept has been provided:
http://www.example.com/photos/showimages.php?dir=<iframe%20src="C:\"%20width=400%20height=400></iframe>
http://www.example.com//photos/showfullimage.php?dir=[dir name][spc]St[spc]Clair&image=<h1>hello</h1>
Solution / Fix
John Beatty Easy PHP Photo Album dir Parameter HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
John Beatty Easy PHP Photo Album dir Parameter HTML Injection Vulnerability
References:
References: