header-logo
Suggest Exploit
vendor:
i-Gallery
by:
..::[ SONiC ]::.. aka ~the_pshyco~
7.5
CVSS
HIGH
Arbitrary File Include, Persistent XSS
CWE
Product Name: i-Gallery
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2010

i-Gallery –Multiple Vulnerability

i-Gallery is a complete online photo gallery. Easy to navigate thumbnails with paging. Enlarged views offer print & email buttons. Secured backend features: create/delete folders, upload/delete images, add descriptions, move images, and much more.

Mitigation:

Source

Exploit-DB raw data:

==============================================================
i-Gallery --Multiple Vulnerability
==============================================================


Name : i-Gallery --Multiple Vulnerability
Date : july 9,2010
Critical Level     :VERY HIGH
vendor URL :   http://www.b-cp.com


Author : ..::[ SONiC ]::.. aka ~the_pshyco~ <sonicdefence[at]gmail.com>

special thanks to : Sid3^effects,r0073r (inj3ct0r.com),L0rd CruSad3r,M4n0j,Bunny,Nishi,MA1201,RJ,D3aD F0x

greetz to :www.topsecure.net ,All ICW members , iNj3cT0r.com, www.andhrahackers.com

special Shoutz : my Girl Frnd [H*****] 
###################################
I'm SONiC member from Inj3ct0r Team
################################### 

Description:

i-Gallery is a complete online photo gallery. Easy to navigate thumbnails with paging. Enlarged views offer print & email buttons. Secured backend features: create/delete folders, upload/delete images, add descriptions, move images, and much more.

#######################################################################################################
Xploit :Arbitrary File Include  Vulnerabilty 

DEMO URL  http://www.site.com/igallery34/viewphoto.asp?i=[file include]&f=fghd&sh=27768&sw=1024

Xploit :Persistent XSS Vulnerabilty 

DEMO URL  http://www.site.com/igallery34/submitphotos.asp?mi=1



###############################################################################################################

# ..::[ SONiC ]::.. aka the_pshyco