vendor:
Yourownbux
by:
Tec-n0x
7.5
CVSS
HIGH
Cookie Modification
264
CWE
Product Name: Yourownbux
Affected Version From: 4
Affected Version To: 4
Patch Exists: Yes
Related CWE: N/A
CPE: a:yourownbux:yourownbux:4.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2008
Yourownbux v4.0 Cookie Modification Exploit
This exploit allows an attacker to modify the cookie of the Yourownbux v4.0 application and gain access to the admin panel. The attacker can add more users to the admin username and use the username and password ‘Tec-n0x’ to gain access. The attacker can use the JavaScript code to modify the cookie.
Mitigation:
The application should be updated to the latest version and the cookie should be set to expire after a certain amount of time.