WEBAlbum < 2.0 Remote Stored Cross Site Scripting Vulnerability

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1052709 漏洞类型
发布时间 2008-06-06 更新时间 2008-06-06
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2008060025
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
 ================================================================

WEBAlbum <= 2.0 Remote Stored Cross Site Scripting Vulnerability

================================================================


AUTHOR : CWH Underground
DATE : 5 June 2008
SITE : www.citec.us


#####################################################
APPLICATION : WEBAlbum
VERSION : <= 2.0
VENDOR : http://www.web-album.org/
DOWNLOAD : http://www.web-album.org/en/download/
#####################################################

 ------------------------------------------------------
     IMPACT: Stored XSS , XSRF , Defacing , etc...  
 ------------------------------------------------------

---Remote XSS Exploit [add comment section]---

Vulnerable in "add comment" section. That's can input HTML code Injection into comment box then send to server.

URL : http://[TARGET]/[webalbum_PATH]/photo_add-c.php
POST Variable: comment			-->		XSS Vulnerabilities
POST Variable: id
POST Variable: category

##################################################################
  Greetz: ZeQ3uL, BAD $ectors, Snapter, Conan, Win7dos, JabAv0C 
##################################################################