Aerosol Posted February 19, 2015 Report Posted February 19, 2015 # Affected software: 4images# Type of vulnerability: clickjacking,xss# URL: http://www.4homepages.de/# Discovered by: Provensec# Website: http://www.provensec.com# Description: 4images is a powerful web-based image gallery managementsystem. Features include comment system, user registration and mangagement,password protected administration area with browser-based upload and HTMLtemplates for page layout and design.# Proof of concept1st:click jacking --:4images was vuln to clickjacking which could be exploited and used todelete categoryhttp://i.imgur.com/vqfz8Lk.pngclickjacking poc -:http://prntscr.com/670r9b2nd: xssadding a new category with xss payload leads to persistent xss vulnhttp://prntscr.com/670rmi-- Best Regards,*Ankit Bharathan.**Save Energy... Save Nature... Go Green...*P *Consider the environment. Please don't print this e-mail unlessabsolutely necessary.*Source Quote