CVE-2004-2443
Jaws 0.3 - Auth Bypass
Title source: llmDescription
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Fernando Quintero · phpwebappsphp
https://www.exploit-db.com/exploits/24256
References (5)
Scores
EPSS
0.0607
EPSS Percentile
90.8%
Details
Status
published
Products (2)
jaws/jaws
0.2
jaws/jaws
0.3
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026