CVE-2006-1838
Fuju News 1.0 - Unauthenticated Authentication Bypass via Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1838. PoCs published by snatcher.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Fuju News 1.0, allowing an attacker to bypass authentication and extract admin credentials via a crafted UNION-based SQL query. It also highlights an authentication bypass by setting a cookie named 'authorized' to '1'.
Description
edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Fuju News 1.0, allowing an attacker to bypass authentication and extract admin credentials via a crafted UNION-based SQL query. It also highlights an authentication bypass by setting a cookie named 'authorized' to '1'.