vendor:
Free Image Hosting Script
by:
RMx - Liz0zim
7.5
CVSS
HIGH
Cookie Injection
79
CWE
Product Name: Free Image Hosting Script
Affected Version From: V1.2.*
Affected Version To: V1.2.*
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Scripteen Free Image Hosting Script V1.2.* (cookie) Admin Password Grabber Exploit
This exploit allows an attacker to gain access to the admin panel of Scripteen Free Image Hosting Script V1.2.* by exploiting a cookie injection vulnerability. The attacker can send a malicious cookie to the server and gain access to the admin panel.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in cookies.