vendor:
Pre Classified Listings PHP
by:
G4N0K
7.5
CVSS
HIGH
Insecure Cookie Handling
264
CWE
Product Name: Pre Classified Listings PHP
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Pre Classified Listings PHP Insecure Cookie Handling
Pre Classified Listings PHP version is vulnerable to insecure cookie handling. An attacker can exploit this vulnerability by setting the adminname and adminid cookie values to admin. This will allow the attacker to gain access to the admin panel.
Mitigation:
Ensure that cookies are set to secure and httpOnly flags are set.