Jump to content

Recommended Posts

Admin Access:

You can access the admin panel by changing the username cookie to admin.

 

Drop Down Menu:

If you edit the Member Type drop down menu on http://www.gamerzworldonline.com/AuthPanel/pages/admin/index.php?action=addmember you can submit arbitrary values

 

Insecure Cookie:

You shouldn't put the username in the cookie.

 

You can log in as any user by setting the auth cookie to their username.

Link to comment
https://forums.phpfreaks.com/topic/70996-beta-test-auth-panel/#findComment-357601
Share on other sites

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.