CVE-2003-1245
Mambo 4.0.12 - Unauthenticated Privilege Escalation via Session ID Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1245. PoCs published by Simen Bergo.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Mambo Site Server by manipulating cookie-based session IDs. It retrieves a session cookie from the logout page, MD5-hashes it, and uses it to gain administrative access.
Description
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Mambo Site Server by manipulating cookie-based session IDs. It retrieves a session cookie from the logout page, MD5-hashes it, and uses it to gain administrative access.