vendor:
Poker League
by:
DaRkLiFe
7.5
CVSS
HIGH
Insecure Cookie Handling
264
CWE
Product Name: Poker League
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
PokerMax Poker League Insecure Cookie Handling Vulnerability
A vulnerability exists in PokerMax Poker League which allows an attacker to gain administrative access to the site by setting a cookie with the username of the administrator. The default username is 'admin' and if it is changed, the attacker can easily find out the username of the admin and substitute it in the exploit command.
Mitigation:
Ensure that the administrator username is not set to the default value and that the cookie is properly secured.