Trackeur De Visiteurs Tracking Evasion Vulnerability
BID:4623
Info
Trackeur De Visiteurs Tracking Evasion Vulnerability
| Bugtraq ID: | 4623 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2002 12:00AM |
| Updated: | Apr 17 2002 12:00AM |
| Credit: | Discovery of this issue is credited to frog frog <[email protected]>. |
| Vulnerable: |
Vincent Courcelle Trackeur de visiteurs 1.0 |
| Not Vulnerable: | |
Discussion
Trackeur De Visiteurs Tracking Evasion Vulnerability
Trackeur de visiteurs is a script for tracking website usage. It is written in PHP and will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
Remote attackers may enable the "no track" flag, which is intended to be used by the website administrator to disable tracking the web activity of certain users. This flag may be enabled via URL manipulation or by submitting a specially crafted cookie.
Exploitation of this issue may aid the attacker in concealing malicious activity which the script might otherwise detect.
Trackeur de visiteurs is a script for tracking website usage. It is written in PHP and will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
Remote attackers may enable the "no track" flag, which is intended to be used by the website administrator to disable tracking the web activity of certain users. This flag may be enabled via URL manipulation or by submitting a specially crafted cookie.
Exploitation of this issue may aid the attacker in concealing malicious activity which the script might otherwise detect.
Exploit / POC
Trackeur De Visiteurs Tracking Evasion Vulnerability
This issue may be exploited with a web browser. The attacker, alternatively, could submit a specially crafted cookie to exploit this issue.
This issue may be exploited with a web browser. The attacker, alternatively, could submit a specially crafted cookie to exploit this issue.
Solution / Fix
Trackeur De Visiteurs Tracking Evasion Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Trackeur De Visiteurs Tracking Evasion Vulnerability
References:
References:
- Security holes in 11 products... (frog frog
) - Trackeur de visiteurs Homepage (Vincent Courcelle)