|
PhpWebGallery Cookie Manipulation Account Compromise Vulnerability
PhpWebGallery is a web application which enables users to create image galleries, and is maintained by Pierrick Le Gall. PhpWebGallery use cookies for authentication. When a user is issued a cookie, the cookie is stored in a non-encrypted format. It is possible for a malicious user to manipulate values in their cookie and authenticate as an arbitrary user of the service, including the administrative account. |
|
|
Privacy Statement |