cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtain session data via a direct request related to the "default session save path."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://code.google.com/p/cookiecheck/ | patch vendor advisory exploit |
http://code.google.com/p/cookiecheck/source/browse/patches/cookiecheck-1.0-security-fix-1.patch?spec=svn11&r=11 | patch exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/49827 | vdb entry |
http://osvdb.org/48865 | vdb entry |