[+] Exploit Title ; Gap Messenger Web Version Multiple Vulnerability
[+] Date : 2018-04-12
[+] Author : 0P3N3R From IRANIAN ETHICAL HACKERS
[+] Vendor Homepage : https://gap.im/
[+] Dork : N/A
[+] Forum : ---
[+] Tested On : windows 10 - kali linux 2.0
[+] Contact : https://telegram.me/WebServer
[+] Description :
[!] Gap is An extremely powerful and popular instant messenger
[!] Gap Has three versions of the desktop - Web and mobile.
[!] More than 100,000 users use it in Iran You can Download it from App Store And bazar
[+] Poc :
[+] Open Redirect :
[!] https://web.gap.im/#/redirect?url=your link here
[!] For Ex :
[!] https://web.gap.im/#/redirect?url=https://google.com
[+] Unvalidated File Upload Vulnerability :
[!] You can upload any files and run on server
[+] Security Level :
[!] Medium
[+] Exploitation Technique:
[!] Remote
[+] Request Method :
[!] GET
[+] Vulnerability Files :
[!] Index
[+] Fix :
[!] Restrict user input or replace bad characters
[+] We Are : [+] 0P3N3R [+] S0!hp