ASP-Nuke Forged Cookie Information Disclosure Vulnerability
BID:4489
Info
ASP-Nuke Forged Cookie Information Disclosure Vulnerability
| Bugtraq ID: | 4489 |
| Class: | Design Error |
| CVE: |
CVE-2002-0523 CVE-2002-0524 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by frog frog <[email protected]>. |
| Vulnerable: |
ASP-Nuke ASP-Nuke RC2 ASP-Nuke ASP-Nuke RC1 |
| Not Vulnerable: |
ASP-Nuke ASP-Nuke RC3 |
Discussion
ASP-Nuke Forged Cookie Information Disclosure Vulnerability
ASP-Nuke is a web based Portal system. It allows users to create accounts and contribute content to the site.
An issue has been reported in ASP-Nuke, which could cause the host to return sensitive system information. A user may modify their authentication cookie in such a way that upon submitting the cookie, the host will return a list of all currently logged in users or the path to the web root.
ASP-Nuke is a web based Portal system. It allows users to create accounts and contribute content to the site.
An issue has been reported in ASP-Nuke, which could cause the host to return sensitive system information. A user may modify their authentication cookie in such a way that upon submitting the cookie, the host will return a list of all currently logged in users or the path to the web root.
Exploit / POC
ASP-Nuke Forged Cookie Information Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ASP-Nuke Forged Cookie Information Disclosure Vulnerability
Solution:
The vendor has acknowledged the existence of this issue. The latest release of ASP-Nuke is RC3 and is not susceptible to this issue.
Solution:
The vendor has acknowledged the existence of this issue. The latest release of ASP-Nuke is RC3 and is not susceptible to this issue.
References
ASP-Nuke Forged Cookie Information Disclosure Vulnerability
References:
References:
- ASP-Nuke : RC1, RC2 (frog frog )
- ASP-Nuke Homepage (ASP-Nuke)