Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

[Full-disclosure] MHL-2006-003 Public Advisory: "ezOnlineGallery" Multip

Subject: [Full-disclosure] MHL-2006-003 Public Advisory: "ezOnlineGallery" Multiple Security Issues
Date: Thu, 26 Oct 2006 21:32:38 -0400
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

MHL-2006-003 - Public Advisory

+-----------------------------------------------------------+
|         ezOnlineGallery Multiple Security Issues          |
+-----------------------------------------------------------+


PUBLISHED ON
  October 26th, 2006


PUBLISHED AT
  http://www.mayhemiclabs.com/advisories/MHL-2006-003.txt
  http://www.mayhemiclabs.com/wiki/wikka.php?wakka=MHL2006003


PUBLISHED BY
  Mayhemic Labs
  http://www.mayhemiclabs.com

  security AT mayhemiclabs DOT com
  GPG key: 0x56143F84


APPLICATION
  ezOnlineGallery
  http://www.ezonlinegallery.com/



AFFECTED VERSIONS
  Versions 1.3 and below


ISSUES
        ezOnlineGallery allows disclosure of certain data about
        the system it is installed on.
        
        1) Valid Path Disclosures
        By editing the album variable when the "show_album"
        action is called on ezgallery.php, an attacker can verify
        the existance of any directory on a system. The system
        will attempt to display an album if the path is valid,
        and will return an error if the path is invalid.
        
        EXAMPLE:
        ezgallery.php?action=show_album&album=../../../../../etc/
        
        2) File Disclosure
        By editing both the album and image variables on image.php
        an attacker can view any JPG, BMP, or PNG that the apache
        process has read access to.
        
        image.php?album=../../home/jrluser/girlfriendpics&image=nude.jpg

WORKAROUNDS
        None at this time

SOLUTIONS
        Upgrade to 1.3.2 Beta


REFERENCES
        ezOnlineGallery - http://www.ezonlinegallery.com/


TIMELINE
        October 26th, 2006
                Vendor/Developer Notified
                Vendor/Developer Fixes Issues
                Public Release

                                
ADDITIONAL CREDIT
  N/A

LICENSE
  Creative Commons Attribution-ShareAlike License
  http://creativecommons.org/licenses/by-sa/2.5
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFFQWG1zjnMaVYUP4QRAmn5AKCggkwoeoEwskcExkJtNnwWC4UBkQCgjetQ
1bjFMzRtPuveUAU6a0+ZaWg=
=yUPA
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

<Prev in Thread] Current Thread [Next in Thread>
  • [Full-disclosure] MHL-2006-003 Public Advisory: "ezOnlineGallery" Multiple Security Issues, Mayhemic Labs Security <=