Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1904. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit leverages insecure cookie handling in CcMail <= 1.0.1, allowing an attacker to set arbitrary cookies and bypass authentication to access the admin area. The PoC provides JavaScript to set the required cookies.
Description
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie.
Exploits (1)
This exploit leverages insecure cookie handling in CcMail <= 1.0.1, allowing an attacker to set arbitrary cookies and bypass authentication to access the admin area. The PoC provides JavaScript to set the required cookies.