CVE-2006-2636
Katy Whitton NewsCMSLite - Unauthenticated Authentication Bypass via loggedIn Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2636.
AI-analyzed exploit summary The exploit demonstrates an authentication bypass vulnerability in NewsCMSLite by setting a crafted cookie value to gain unauthorized access. The JavaScript snippet directly manipulates the 'loggedIn' cookie, bypassing proper authentication mechanisms.
Description
newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ".
Exploits (1)
The exploit demonstrates an authentication bypass vulnerability in NewsCMSLite by setting a crafted cookie value to gain unauthorized access. The JavaScript snippet directly manipulates the 'loggedIn' cookie, bypassing proper authentication mechanisms.