[+] Exploit Title: Coppermine Photo Gallery 1.5.36 Cross Site Scripting [+] Exploit Author: Ehsan Hosseini [+] Date: 27/7/2015 [+] Vendor Homepage: http://coppermine-gallery.net/ [+] Software Link: http://sourceforge.net/projects/coppermine/files/Coppermine/1.5.x/cpg1.5.36.zip/download [+] Version: 1.5.36 [+] Tested on: Windows [+] CVE : N/A =============================== Introduction : Coppermine Photo Gallery is a multi-purpose fully-featured and integrated web picture gallery script written in PHP. Coppermine Photo Gallery suffers from a Cross site scripting vulnerability. =============================== Vulnerable file is : localhost/cpg15x/install_classic.php =============================== Vulnerable Code : 316 : 323 : 313 : 345 : 352 : 359 : 366 : 373 : 390 : =============================== Exploit :
================================================== Path : To fix this vulnerability you use htmlspecialchars() function . And other lines, too. Discovered By : Ehsan Hosseini.