Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Vehicle-Service-Management-System-Multiple-Cookie-Stealing-Leads-to-Full-Account-Takeover — CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover. | Kitploit
Tools/GitHubGitHub/sanupl/vehicle-service-management-system-multiple-cookie-stealing-leads-to-full-account-takeover
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRed Teaming
GitHubsanupl/vehicle-service-management-system-multiple-cookie-stealing-leads-to-full-account-takeover

Vehicle-Service-Management-System-Multiple-Cookie-Stealing-Leads-to-Full-Account-Takeover

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

View Repository
3 months agoNot yet reviewed

CVE-2021-46067

Exploit Title: Vehicle Service Management System - 'Multiple' Cookie Stealing Leads to Full Account Takeover

Exploit Author: SANU P.L

CVE: CVE-2021-46067

CVSS: 9.8 CRITICAL

References:

  • https://www.plsanu.com/vehicle-service-management-system-multiple-cookie-stealing-leads-to-full-account-takeover
  • https://nvd.nist.gov/vuln/detail/CVE-2021-46067
  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46067

Description:

In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

1. Vehicle Service Management System - 'MyAccount' (/admin/?page=user)

Exploit:

  1. Login to the admin panel http://localhost/vehicle_service/admin
  2. Navigate to My Account section http://localhost/vehicle_service/admin/?page=user
  3. Generate the Webhook URL - https://webhook.site
  4. Copy the Webhook unique URL and paste it in the below html code.

Payload:

root@kitploit:~
<!DOCTYPE html>
<html>
<title>Cookie Stealing</title>
<body>

</body>
</html>
  1. Save the above html code For Ex:Cookie Stealing.html
  2. In My Account Section enter all the required details and browse the html file in Avatar.
  3. Click on update button.
  4. Open the avatar image in new tab and check the Webhook status.
  5. We got the request it contains PHPSESSID.
  6. Copy the PHPSESSID value and open any another browser.
  7. Visit the admin panel http://localhost/vehicle_service/admin
  8. Check the cookie values and change the PHPSESSID value to copied PHPSESSID value.
  9. Now access the admin panel http://localhost/vehicle_service/admin
  10. Successfully loggedin to the account. Account Takeover Successful.

2. Vehicle Service Management System - 'User List' (/admin/?page=user/manage_user)

Exploit:

  1. Login to the admin panel http://localhost/vehicle_service/admin
  2. Navigate to User List section and click on Create New button.
  3. Generate the Webhook URL - https://webhook.site
  4. Copy the Webhook unique URL and paste it in the below html code.

Payload:

root@kitploit:~
<!DOCTYPE html>
<html>
<title>Cookie Stealing</title>
<body>

</body>
</html>
  1. Save the above html code For Ex:Cookie Stealing.html
  2. In Create New User Section enter all the required details and browse the html file in Avatar.
  3. Click on Save button.
  4. Open the avatar image in new tab and check the Webhook status.
  5. We got the request it contains PHPSESSID.
  6. Copy the PHPSESSID value and open any another browser.
  7. Visit the admin panel http://localhost/vehicle_service/admin
  8. Check the cookie values and change the PHPSESSID value to copied PHPSESSID value.
  9. Now access the admin panel http://localhost/vehicle_service/admin
  10. Successfully loggedin to the account. Account Takeover Successful.

3. Vehicle Service Management System - 'Settings-System Logo' (/admin/?page=system_info)

Exploit:

  1. Login to the admin panel http://localhost/vehicle_service/admin
  2. Navigate to Settings section http://localhost/vehicle_service/admin/?page=system_info
  3. Generate the Webhook URL - https://webhook.site
  4. Copy the Webhook unique URL and paste it in the below html code.

Payload:

root@kitploit:~
<!DOCTYPE html>
<html>
<title>Cookie Stealing</title>
<body>

</body>
</html>
  1. Save the above html code For Ex:Cookie Stealing.html
  2. In Settings Section enter all the required details and browse the html file in System Logo.
  3. Click on update button.
  4. Open the System Logo image in new tab and check the Webhook status.
  5. We got the request it contains PHPSESSID.
  6. Copy the PHPSESSID value and open any another browser.
  7. Visit the admin panel http://localhost/vehicle_service/admin
  8. Check the cookie values and change the PHPSESSID value to copied PHPSESSID value.
  9. Now access the admin panel http://localhost/vehicle_service/admin
  10. Successfully loggedin to the account. Account Takeover Successful.

4. Vehicle Service Management System - 'Settings-Website Cover' (/admin/?page=system_info)

Exploit:

  1. Login to the admin panel http://localhost/vehicle_service/admin
  2. Navigate to Settings section http://localhost/vehicle_service/admin/?page=system_info
  3. Generate the Webhook URL - https://webhook.site
  4. Copy the Webhook unique URL and paste it in the below html code.

Payload:

root@kitploit:~
<!DOCTYPE html>
<html>
<title>Cookie Stealing</title>
<body>

</body>
</html>
  1. Save the above html code For Ex:Cookie Stealing.html
  2. In Settings Section enter all the required details and browse the html file in Website Cover.
  3. Click on update button.
  4. Open the Website Cover image in new tab and check the Webhook status.
  5. We got the request it contains PHPSESSID.
  6. Copy the PHPSESSID value and open any another browser.
  7. Visit the admin panel http://localhost/vehicle_service/admin
  8. Check the cookie values and change the PHPSESSID value to copied PHPSESSID value.
  9. Now access the admin panel http://localhost/vehicle_service/admin
  10. Successfully loggedin to the account. Account Takeover Successful.

Impact:

An attacker upload malicious html file it redirects to the third party website and cookies are exposed in the request. It leads to Full Account Takeover.

Mitigation:

It is recommended to validate the file upload functionality and Perform Secondary Checks in the session.

Download Tool