AOH :: HP Unsorted S :: TB13585.HTM

SimpleGallery v0.1.3 (index.php) Cross-Site Scripting Vulnerability



SimpleGallery v0.1.3 (index.php) Cross-Site Scripting Vulnerability
SimpleGallery v0.1.3 (index.php) Cross-Site Scripting Vulnerability



# SimpleGallery v0.1.3 (index.php) Cross-Site Scripting Vulnerability
# Download:
# http://richie.7crows.net/projects/gnu/simpleGallery/
# Bug found by Jose Luis G=F3ngora Fern=E1ndez / JosS
# Contact: sys-project[at]hotmail.com
# Spanish Hackers Team
# www.spanish-hackers.com
# /server irc.freenode.net /join #fullsecure
# d0rk: "Powered by SimpleGallery"
# Stop lammer

# Exploit In (XSS):

../PATH/index.php?album=[XSS]
http://www.example.com/PATH/index.php?album=[XSS]

# Cross Siting Scripting (Code):

">


 //---------------------------------------\\

Greetz To: All Hackers
Jose Luis G=F3ngora Fern=E1ndez / JosS!

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.