CVE-2008-3508
LiteNews 0.1 - Unauthenticated Authentication Bypass via Admin Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3508. PoCs published by Scary-Boys.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie handling vulnerability in LiteNews 1.2, allowing an attacker to bypass authentication by setting an admin cookie via JavaScript. The admin panel only checks for the presence of the cookie, granting unauthorized access.
Description
LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie.
Exploits (1)
This exploit demonstrates an insecure cookie handling vulnerability in LiteNews 1.2, allowing an attacker to bypass authentication by setting an admin cookie via JavaScript. The admin panel only checks for the presence of the cookie, granting unauthorized access.