|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 107
Members: 0
Total: 107
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Coppermine login mechanism... |
|
Posted: Sun Apr 13, 2008 4:35 pm |
|
|
V3ntus |
Beginner |
|
|
Joined: Apr 13, 2008 |
Posts: 1 |
|
|
|
|
|
|
|
Hello
I tested Coppermine Photo Gallery 1.4.13 on my localhost and with reflected xss i stole admin cookie. I tried to use this cookie to log as an admin, but I dicovered that cookie from user and from admin are the same. What type of login mechanism is in this gallery? What Can I do with steal cookie?
I'm sorry for my English - I still learn this language. |
|
|
|
|
www.waraxe.us Forum Index -> Cross-site scripting aka XSS
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|