Exploit phpRPG 0.8 - '/tmp' Directory PHPSESSID Cookie Session Hijacking

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
30888
Проверка EDB
  1. Пройдено
Автор
MICHAEL BROOKS
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2007-6470
Дата публикации
2007-12-15
Код:
source: https://www.securityfocus.com/bid/26884/info

phpRPG is prone to two vulnerabilities:

- An SQL-injection vulnerability
- A vulnerability that lets remote attackers gain access to sessions.

Exploiting these issues may allow an unauthorized user to steal sessions, access or modify data, or exploit latent vulnerabilities in the underlying database.

This issue affects phpRPG 0.8.0; other versions may also be affected. 

http://www.example.com/phpRPG-0.8.0/tmp/
 
Источник
www.exploit-db.com

Похожие темы