Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17384
HistoryJun 28, 2007 - 12:00 a.m.

XEForum Cookie Modification Privilege Escalation Vulnerability

2007-06-2800:00:00
vulners.com
11

-------------------------------------------------------------------- XEForum Cookie Modification
Privilege Escalation Vulnerability

Vulnerable product: XEForum
Vendor: http://www.xeforum.com/

Date:

Found: Jun 26, 2007

Vulnerability:

XeForum contains a flaw that may allow a remote attacker to gain administrative privileges.
Modifying contained cookie you can change of session and to even enter like administrator.

Cookie:

: Cookie: xeforum="Your Username" :

change to:

: Cookie: xeforum="Admin Username" :

Credit:

Firewall
Firewall of Peru
[email protected]
Greetz to Swp-Scene And Revolutionz
http://4firewall.uni.cc