CVE-2008-1904

Cicoandcico CcMail <1.0.1 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1904. PoCs published by t0pP8uZz.

AI-analyzed exploit summary This exploit leverages insecure cookie handling in CcMail <= 1.0.1, allowing an attacker to set arbitrary cookies and bypass authentication to access the admin area. The PoC provides JavaScript to set the required cookies.

Description

Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie.

Exploits (1)

exploitdb WORKING POC VERIFIED
by t0pP8uZz · textwebappsphp
https://www.exploit-db.com/exploits/5433

This exploit leverages insecure cookie handling in CcMail <= 1.0.1, allowing an attacker to set arbitrary cookies and bypass authentication to access the admin area. The PoC provides JavaScript to set the required cookies.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: CcMail <= 1.0.1
No auth needed
Prerequisites: Access to the target's cookie storage (e.g., via XSS or manual execution)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5433
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29812
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41797
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28751

Scores

EPSS 0.0219
EPSS Percentile 80.0%

Details

CWE
CWE-287
Status published
Products (2)
cicoandcico/ccmail 1.0
cicoandcico/ccmail < 1.0.1
Published Apr 22, 2008
Tracked Since Feb 18, 2026