Coppermine 1.4.8~Parameter Cleanup System ByPass~Registering Global Varables
Posted by imei on June 20th, 2006——————-Summary—————-
Software: CPG Coppermine Photo Gallery
Sowtware’s Web Site: http://coppermine.sourceforge.net/
Versions: 1.4.8.stable
Class: Remote
Status: Unpatched
Exploit: Available
Discovered by: imei addmimistrator
Risk Level: High
—————–Description—————
Coppermine Photo Gallery has a logical design fault that will result to bypassing anti-XSS-Injection–RegGlobal-System.
It is because that process of cleaning user suplied data checks that if we have any varable
that exists in querystrings(or same)? If so it deletes that […]