Exploit Expinion.net News Manager Lite 2.5 - 'NEWS_LOGIN?admin' Cookie Authentication Bypass

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
23863
Проверка EDB
  1. Пройдено
Автор
MANUEL LOPEZ
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
cve-2004-1847
Дата публикации
2004-03-20
Код:
source: https://www.securityfocus.com/bid/9935/info
     
Multiple vulnerabilities have been identified in the application that may allow an attacker to carry out SQL injection, cross-site scripting, and account hijacking attacks.
     
The issues exist in the 'comment_add.asp', 'search.asp', 'category_news_headline.asp', 'more.asp', 'category_news.asp', and 'ews_sort.asp' scripts. Further more a cookie account hijacking issue was also discovered in the application that may allow a remote attacker to gain administrative access to application's administrative interface.
     
News Manager Lite 2.5 is reported to be affected by these issues, however, other versions may be affected as well.

Cookie: NEWS%5FLOGIN=ADMIN=1&ID=1
 
Источник
www.exploit-db.com

Похожие темы