Portix-PHP Cookie Manipulation Vulnerability
BID:4041
Info
Portix-PHP Cookie Manipulation Vulnerability
| Bugtraq ID: | 4041 |
| Class: | Design Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Feb 04 2002 12:00AM |
| Updated: | Feb 04 2002 12:00AM |
| Credit: | Discovery of this issue is credited to frog frog <[email protected]>. |
| Vulnerable: |
Portix-PHP Portix-PHP 0.4.2 Portix-PHP Portix-PHP 0.4 |
| Not Vulnerable: | |
Discussion
Portix-PHP Cookie Manipulation Vulnerability
Portix-PHP is freely available web portal software. It is written in PHP and will run on most Unix and Linux variants.
Portix-PHP uses non-expiring cookies for session management. It is possible for a malicious user to manipulate values in their cookie to gain access to administrative pages on the web portal.
Successful hijacking of the administrative account will permit the malicious user to access all of the web portal's administrative facilities.
Portix-PHP is freely available web portal software. It is written in PHP and will run on most Unix and Linux variants.
Portix-PHP uses non-expiring cookies for session management. It is possible for a malicious user to manipulate values in their cookie to gain access to administrative pages on the web portal.
Successful hijacking of the administrative account will permit the malicious user to access all of the web portal's administrative facilities.
Exploit / POC
Portix-PHP Cookie Manipulation Vulnerability
Change the values in the stored cookie to the following:
name=access value=ok
Change the values in the stored cookie to the following:
name=access value=ok
Solution / Fix
Portix-PHP Cookie Manipulation Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Portix-PHP Cookie Manipulation Vulnerability
References:
References:
- Failles dans le portail PHP Portix (BAL Crew)
- Portix-PHP Homepage (Portix-PHP)