|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[Full-Disclosure] Authentication flaw in Web Wiz forum
From: Alexander (pk95
yandex.ru)
Date: Tue Mar 02 2004 - 15:20:30 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Product: Web Wiz forum 7.0-7.7a www.webwizforum.com
Risk: Medium
Date: 02 March, 2004
Autor: Pig Killer and Michael ( www.SecurityLab.ru)
When user log on forum, for his cookies identification forum using User_code
value from tblAutor table from underlying database, which doesn't change
with changing of password. As a result, when user change password, he can
register in the forum using old cookies. As a result, if users cookies was
compromised (for example by XSS), then even password changing will doesn't
protect his account from unauthorized using.
The forum also allows logged in user to change the password without entering
the old one. Thus, having cookie, you can change the password without
knowing the old one.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]