Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | MHL-2006-003 Public Advisory: "ezOnlineGallery" Multiple Security Issues |
|---|---|
| Date: | Fri, 27 Oct 2006 09:03:11 -0400 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 MHL-2006-003 - Public Advisory +-----------------------------------------------------------+ | ezOnlineGallery Multiple Security Issues | +-----------------------------------------------------------+ PUBLISHED ON October 26th, 2006 PUBLISHED AT http://www.mayhemiclabs.com/advisories/MHL-2006-003.txt http://www.mayhemiclabs.com/wiki/wikka.php?wakka=MHL2006003 PUBLISHED BY Mayhemic Labs http://www.mayhemiclabs.com security AT mayhemiclabs DOT com GPG key: 0x56143F84 APPLICATION ezOnlineGallery http://www.ezonlinegallery.com/ AFFECTED VERSIONS Versions 1.3 and below ISSUES ezOnlineGallery allows disclosure of certain data about the system it is installed on. 1) Valid Path Disclosures By editing the album variable when the "show_album" action is called on ezgallery.php, an attacker can verify the existance of any directory on a system. The system will attempt to display an album if the path is valid, and will return an error if the path is invalid. EXAMPLE: ezgallery.php?action=show_album&album=../../../../../etc/ 2) File Disclosure By editing both the album and image variables on image.php an attacker can view any JPG, BMP, or PNG that the apache process has read access to. image.php?album=../../home/jrluser/girlfriendpics&image=nude.jpg WORKAROUNDS None at this time SOLUTIONS Upgrade to 1.3.2 Beta REFERENCES ezOnlineGallery - http://www.ezonlinegallery.com/ TIMELINE October 26th, 2006 Vendor/Developer Notified Vendor/Developer Fixes Issues Public Release ADDITIONAL CREDIT N/A LICENSE Creative Commons Attribution-ShareAlike License http://creativecommons.org/licenses/by-sa/2.5 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFFQWG1zjnMaVYUP4QRAmn5AKCggkwoeoEwskcExkJtNnwWC4UBkQCgjetQ 1bjFMzRtPuveUAU6a0+ZaWg= =yUPA -----END PGP SIGNATURE-----
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | TSLSA-2006-0059 - postgresql, Trustix Security Advisor |
|---|---|
| Next by Date: | MiniBILL v2006-10-10 (config[page_dir] Remote File Include Vulnerability, xorontr |
| Previous by Thread: | TSLSA-2006-0059 - postgresql, Trustix Security Advisor |
| Next by Thread: | MiniBILL v2006-10-10 (config[page_dir] Remote File Include Vulnerability, xorontr |
| Indexes: | [Date] [Thread] [Top] [All Lists] |