Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
SQL Injection by using Cookie Poisoning for Website Baker Version 2.6.5 and before Jan 22 2007 10:36PM
Rolf Huisman (r l r huisman home nl)
Website Baker Version 2.6.5 and before contains a SQL injection.
This can be exploited by using Cookie Poisoning

Manufacturer was notified, but want to ignore the request pending release version 3.0

Poison the cookie for the login page with the REMEMBER_KEY variable with a standard sql injection (...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus