Snipe Gallery Multiple Input Validation Vulnerabilities

No exploit is required.

Example URIs have been provided:

http://www.example.com/view.php?gallery_id=[SQL]
http://www.example.com/image.php?page=1&gallery_id=1&image_id=[SQL]

http://www.example.com/search.php?keyword=%22%3E%3Cscript%3Ealert%28%
27r0t%27%29%3C%2Fscript%3E&search_cat=&search_type=and


 

Privacy Statement
Copyright 2010, SecurityFocus