Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  CGI bugs

  Xpede many vulnerabilities

  postnuke v 0.7.0.3 remote command execution

  CGIscript.net - csSearch.cgi - Remote Code Execution (up to 17,000 sites vulnerable)

  Instant Web Mail additional POP3 commands and mail headers

From:MOD <br014c1155_(at)_blueyonder.co.uk>
Date:26.03.2002
Subject:Cookie vulnerability in Alguest guestbook (PHP)

Alguest is a guestbook programmed in PHP, there is a major flaw in it which
enables any user to access the admin panel. The script can be downloaded
from
http://www.hotscripts.com/cgi-bin/dload.cgi?ID=14105
It has a flaw in which cookie data isn't properly checked for administrator
rights (username, password), it only checks if the cookie is present
"elseif(isset($admin))" Therefore anyone can just create a cookie and gain
access to administrator privledges.
A solution might be this "elseif(isset($HTTP_COOKIE_VARS['admin'] ==
$password && $username))" but I haven't tested it so I can not guarantee it.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru