exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ZenPhoto 1.4.0.3 Cross Site Scripting

ZenPhoto 1.4.0.3 Cross Site Scripting
Posted Apr 22, 2011
Authored by Saif El-Sherei

ZenPhoto version 1.4.0.3 suffers from a x-forwarded-for HTTP header persistent cross site scripting vulnerability.

tags | exploit, web, xss
SHA-256 | 31943b0ed4c18db66f55e83de7afe3e61f31ce216337eebd49027363f3ec405c

ZenPhoto 1.4.0.3 Cross Site Scripting

Change Mirror Download
# Exploit Title: ZenPhoto 1.4.0.3 patched 2011-4-19 x-forwarded-for HTTP
Header presisitent XSS
# Date: 21-4-2011
# Author: Saif El-Sherei
# Software Link: http://zenphoto.googlecode.com/files/zenphoto-1.4.0.3.zip
# Version: 1.4.0.3 latest updated 2011-4-19
# Tested on:FF 3.0.15, IE 8

Info:

Zenphoto is an answer to lots of calls for an online gallery solution that
just makes sense. After years of bloated software that does everything and
your dishes, zenphoto just shows your photos, simply. It's got all the
functionality and "features" you need, and nothing you don't. Where the old
guys put in a bunch of modules and junk, we put a lot of thought. We hope
you agree with our philosopy: simpler is better.

Details:

failure to sanitize "x-forwarded-for" HTTP header in security logs before
being displayed in "zp-core/admin-logs.php", could allow a remote attacker
to inject malicious HTML code by altering the "x-forwarded-for" HTTP header
using either an intercepting proxy or manual requests in security logs and
attack any user with sufficient privilege to access "Security-logs", usually
appliaction administrators by presistent XSS.

POC:

<script>alert('Saif was Here');</script>

Regards,

Saif El-Sherei
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close