Alguest Cookie Falsification Vulnerability
BID:4355
Info
Alguest Cookie Falsification Vulnerability
| Bugtraq ID: | 4355 |
| Class: | Design Error |
| CVE: |
CVE-2002-0491 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this issue is credited to "MOD" <[email protected]>. |
| Vulnerable: |
Alguest Alguest 1.0 |
| Not Vulnerable: | |
Discussion
Alguest Cookie Falsification Vulnerability
Alguest is a guestbook program, written in PHP and back-ended by a MySQL database. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
Alguest is prone to an issue which may enable a remote attacker to gain administrative access to the guestbook.
Alguest administrative cookies are not properly checked for administrative rights (via a shared secret, credentials such as username/password, etc.). As a result, it is trivial for a remote attacker to falsify an administrative cookie.
Alguest is a guestbook program, written in PHP and back-ended by a MySQL database. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
Alguest is prone to an issue which may enable a remote attacker to gain administrative access to the guestbook.
Alguest administrative cookies are not properly checked for administrative rights (via a shared secret, credentials such as username/password, etc.). As a result, it is trivial for a remote attacker to falsify an administrative cookie.
Exploit / POC
Alguest Cookie Falsification Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Alguest Cookie Falsification Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.