PhotoStore Multiple Cross-Site Scripting Vulnerabilities

2006.10.01
Credit: meto5757
Risk: Low
Local: No
Remote: Yes
CWE: CWE-Other


CVSS Base Score: 5.1/10
Impact Subscore: 6.4/10
Exploitability Subscore: 4.9/10
Exploit range: Remote
Attack complexity: High
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

################################################# PhotoStore Multiple Cross-Site Scripting Vulnerabilities ------------------------------------------------- site : http://www.ktools.net/photostore/ ------------------------------------------------- Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks. ------------------------------------------------- Exploite : ---------- http://www.example.net/[path]/details.php?gid=[xss] http://www.example.net/[path]/view_photog.php?photogid=[xss] -------------------------------------------------- Discoverd by : meto5757 of rootshell security group -------------------------------------------------- greets : Ironfist , sverde1 , Dr.Viru$ , craziest (miss u!) & all my friends :) --------------------------------------------------


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top