ASP-Nuke Plaintext Cookie Authentication Credentials User Account Compromise Vulnerability
BID:4484
Info
ASP-Nuke Plaintext Cookie Authentication Credentials User Account Compromise Vulnerability
| Bugtraq ID: | 4484 |
| Class: | Design Error |
| CVE: |
CVE-2002-0522 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by frog frog <[email protected]>. |
| Vulnerable: |
ASP-Nuke ASP-Nuke RC2 ASP-Nuke ASP-Nuke RC1 |
| Not Vulnerable: |
ASP-Nuke ASP-Nuke RC3 |
Discussion
ASP-Nuke Plaintext Cookie Authentication Credentials User Account Compromise Vulnerability
ASP-Nuke is a web based Portal system. It allows users to create accounts and contribute content to the site.
ASP-Nuke use cookies for authentication. When a user is issued a cookie, the cookie is stored in a non-encrypted format. It is possible for a malicious user to manipulate values in their cookie and authenticate as an arbitrary user of the service, including the administrative account.
ASP-Nuke is a web based Portal system. It allows users to create accounts and contribute content to the site.
ASP-Nuke use cookies for authentication. When a user is issued a cookie, the cookie is stored in a non-encrypted format. It is possible for a malicious user to manipulate values in their cookie and authenticate as an arbitrary user of the service, including the administrative account.
Exploit / POC
ASP-Nuke Plaintext Cookie Authentication Credentials User Account Compromise Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
ASP-Nuke Plaintext Cookie Authentication Credentials User Account Compromise Vulnerability
Solution:
The vendor has acknowledged the existence of this issue. The latest release of ASP-Nuke is RC3 and is not susceptible to this issue.
Solution:
The vendor has acknowledged the existence of this issue. The latest release of ASP-Nuke is RC3 and is not susceptible to this issue.
References
ASP-Nuke Plaintext Cookie Authentication Credentials User Account Compromise Vulnerability
References:
References:
- ASP-Nuke : RC1, RC2 (frog frog )
- ASP-Nuke Homepage (ASP-Nuke)