CVE-2008-2282
Internet Photoshow and Internet Photoshow SE - Unauthenticated Authentication Bypass via login_admin Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2282. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie handling vulnerability in Internet Photoshow SE, allowing an attacker to gain admin access by setting a crafted cookie via JavaScript. The PoC provides a simple one-liner to bypass authentication and access the admin panel.
Description
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true.
Exploits (1)
This exploit demonstrates an insecure cookie handling vulnerability in Internet Photoshow SE, allowing an attacker to gain admin access by setting a crafted cookie via JavaScript. The PoC provides a simple one-liner to bypass authentication and access the admin panel.