FreeWebshop Cookie Security Bypass Vulnerability
BID:26894
Info
FreeWebshop Cookie Security Bypass Vulnerability
| Bugtraq ID: | 26894 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2007 12:00AM |
| Updated: | Dec 18 2007 02:31AM |
| Credit: | k1tk4t discovered this vulnerability. |
| Vulnerable: |
FreeWebshop FreeWebshop 2.2.7 FreeWebshop FreeWebshop 2.2.2 FreeWebshop FreeWebshop 2.2.1 FreeWebshop FreeWebshop 2.2 FreeWebshop FreeWebshop 2.1 |
| Not Vulnerable: | |
Discussion
FreeWebshop Cookie Security Bypass Vulnerability
FreeWebshop is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
Exploiting this issue may allow an attacker to obtain sensitive information and compromise the application; other attacks are also possible.
This issue affects versions prior to FreeWebshop 2.2.7.
FreeWebshop is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
Exploiting this issue may allow an attacker to obtain sensitive information and compromise the application; other attacks are also possible.
This issue affects versions prior to FreeWebshop 2.2.7.
Exploit / POC
FreeWebshop Cookie Security Bypass Vulnerability
Attackers can use standard tools to exploit this issue.
The following proof-of-concept code is available:
Attackers can use standard tools to exploit this issue.
The following proof-of-concept code is available:
Solution / Fix
FreeWebshop Cookie Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FreeWebshop Cookie Security Bypass Vulnerability
References:
References:
- FreeWebShop Homepage (FreeWebShop)
- FreeWebshop <= 2.2.7 - (cookie) Admin Password Grabber Exploit (k1tk4t)