RETIRED: Absolute File Send .Net Cookie Authentication Bypass Vulnerability
BID:32002
Info
RETIRED: Absolute File Send .Net Cookie Authentication Bypass Vulnerability
| Bugtraq ID: | 32002 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2008 12:00AM |
| Updated: | Apr 27 2009 04:16PM |
| Credit: | Hakxer |
| Vulnerable: |
XIGLA SOFTWARE Absolute File Send .NET 1.0 |
| Not Vulnerable: | |
Discussion
RETIRED: Absolute File Send .Net Cookie Authentication Bypass Vulnerability
Absolute File Send .Net is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Attackers can exploit this vulnerability to gain administrative access, which may aid in further attacks.
Absolute File Send .Net 1.0 is vulnerable; other versions may also be affected.
NOTE: This issue is being retired because the vulnerability affects only the demonstration version at the vendor's site. The vendor states that distributed versions are not affected.
Absolute File Send .Net is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Attackers can exploit this vulnerability to gain administrative access, which may aid in further attacks.
Absolute File Send .Net 1.0 is vulnerable; other versions may also be affected.
NOTE: This issue is being retired because the vulnerability affects only the demonstration version at the vendor's site. The vendor states that distributed versions are not affected.
Exploit / POC
RETIRED: Absolute File Send .Net Cookie Authentication Bypass Vulnerability
Attackers may exploit this issue through a browser.
The following example code is available:
javascript:document.cookie="xlaAFSuser=p=admin";
Attackers may exploit this issue through a browser.
The following example code is available:
javascript:document.cookie="xlaAFSuser=p=admin";
Solution / Fix
RETIRED: Absolute File Send .Net Cookie Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Absolute File Send .Net Cookie Authentication Bypass Vulnerability
References:
References:
- Absolute File Send .NET Homepage (XIGLA SOFTWARE)