header-logo
Suggest Exploit
vendor:
Gallery Kys
by:
Osirys
7.5
CVSS
HIGH
Admin Password Disclosure / Permanent XSS
200, 79
CWE
Product Name: Gallery Kys
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:advancescripts:gallery_kys
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Gallery Kys 1.0 Admin Password Disclosure / Permanent XSS

Gallery Kys 1.0 is vulnerable to an admin password disclosure and permanent XSS. The admin password is stored in plaintext in the config.inc file, which can be accessed directly. Additionally, the uploadform.php file does not properly filter user input, allowing an attacker to inject malicious JavaScript code into the description field.

Mitigation:

Don't allow direct access to the config.inc file and change its extension to .php. Filter user input before printing it in the HTML code.
Source

Exploit-DB raw data:

[START]

#########################################################################################
[0x01] Informations:

Script         : Gallery Kys 1.0
Download       : http://www.advancescripts.com/djump.php?ID=6285
Vulnerability  : Admin Password Disclosure / Permanent XSS
Author         : Osirys
Contact        : osirys[at]live[dot]it
Website        : http://osirys.org

#########################################################################################
[0x02] Bug: [Admin Password Disclosure]
######

Bugged file is: /[path]/config.inc

[CODE]

<?
$adpass="admin"; //change admin to your password of choice
?>

[/CODE]

Just going at this path you will get Administrator's password.

[!] FIX: Don't allow direct access to this file and change it's extension with .php


[!] EXPLOIT: /[path]/config.inc
             $adpass="admin_pwd";

#########################################################################################
[0x03] Bug: [Permanent XSS]
######

Bugged file is: /[path]/uploadform.php

[CODE]

$fp =fopen($file, "w+");
$name=stripslashes($name);
$des=stripslashes($des);
$code=stripslashes($code);
$author=stripslashes($author);
$w ="name=".$name."&price=".$price."&code=".$code."&des=".$des."&author=".$author."&mail=".$mail."&date=".$date."&web=".$web;

[/CODE]

Once we got Administrator's password, we are able to log in.

Login at this path: /[path]/admin.php

Then just go at this path: /[path]/uploadform.php

Fill the forms, and put in description form the following code:

<script>alert("XSS")</script>

After this action, data that we typed in the upload form, will be saved on .txt files.
In index.php source code, we can see that the script opens the .txt files, and prints
it's values directly in html code. 


[!] FIX: Filter variables before printing them in the html code.
         preg_math the < > " chars. Filter illegal chars.

#########################################################################################

[/END]

# milw0rm.com [2009-01-19]