vendor:
CommunityManager.NET
by:
Sense of Security Labs
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: CommunityManager.NET
Affected Version From: v6.7
Affected Version To: v6.7
Patch Exists: YES
Related CWE: Not yet assigned
CPE: a:elcom_technology:communitymanager.net
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: IIS with ASP.NET
2010
Elcom CommunityManager.NET Auth Bypass Vulnerability – Security Advisory – SOS-10-004
The web application uses cookie parameters passed via HTTP requests to identify which user is logged in. Authentication routines can be bypassed by simply appending the below POC string to a cookie which already contains a valid ASP.NET session ID. The value given to the various cookie parameters indicates the specific user ID for the application user the attacker wishes to impersonate.
Mitigation:
Vendor patch