AOH :: HP Unsorted A :: TB12304.HTM

Abledesign Dynamic Picture Frame XSS



Abledesign Dynamic Picture Frame XSS
Abledesign Dynamic Picture Frame XSS



Vendor Site: http://abledesign.com/ 
Version affected: ???
Demo: http://abledesign.com/demo/pframe.php 
Class: Input Validation Error

Overview: Dynamic Picture Frame is a PHP script which allows you to add a variety of picture frames of any size to images on your website. Dynamic Picture Frame fails to sufficiently sanitize user-supplied input data in "Image URL" text box by pressing the "submit" button. 

Example:
1.XSS


Discovered by: Joshua Morin (morin.josh@gmail.com) 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.