WikyBlog-1.7.3rc2 Mullti Vulnerability
This script is vulnerable to Cookie manipulation attacks. By injecting a custom HTTP header or by injecting a META tag, it is possible to alter the cookies stored in the browser. Attackers will normally manipulate cookie values to fraudulently authenticate themselves on a web site. This vulnerability affects /Wiky/index.php/Special/Main/Templates. By exploiting this vulnerability, an attacker may conduct a session fixation attack. In a session fixation attack, the attacker fixes the user's session ID before the user even logs into the target server, thereby eliminating the need to obtain the user's session ID afterwards. This script is also vulnerable to Cross Site Scripting attacks. By injecting malicious JavaScript code, it is possible to execute arbitrary code in the browser of the victim. Attackers will normally use this vulnerability to steal the session ID of the victim, thereby allowing them to hijack the user's session.