CVE-2008-1904
Cicoandcico CcMail <1.0.1 - Auth Bypass
Title source: llmDescription
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by t0pP8uZz · textwebappsphp
https://www.exploit-db.com/exploits/5433
Scores
EPSS
0.0407
EPSS Percentile
88.4%
Classification
CWE
CWE-287
Status
draft
Affected Products (2)
cicoandcico/ccmail
< 1.0.1
cicoandcico/ccmail
Timeline
Published
Apr 22, 2008
Tracked Since
Feb 18, 2026