vendor:
Gobbl CMS
by:
x0r
5.5
CVSS
MEDIUM
Cookie Handling
119
CWE
Product Name: Gobbl CMS
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
Gobbl Cms 1.0 I.Cookie Hand.
The 'auth.php' file in Gobbl CMS 1.0 does not properly validate user input, allowing an attacker to set the 'auth' cookie to 'ok' and gain unauthorized access to the admin panel. The exploit involves using a JavaScript code to set the cookie and then accessing the 'menu.php' file in the admin directory.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper input validation and authentication mechanisms in the 'auth.php' file. Additionally, the use of secure cookies and session management techniques can help prevent unauthorized access.