CVE-2008-4600

PokerMax Poker League Tournament Script 0.13 - Unauthenticated Authentication Bypass via ValidUserAdmin Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4600. PoCs published by DaRkLiFe.

AI-analyzed exploit summary This exploit leverages insecure cookie handling in PokerMax Poker League to bypass authentication by setting the 'ValidUserAdmin' cookie to 'admin'. It allows an attacker to gain administrative access without credentials.

Description

configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DaRkLiFe · textwebappsphp
https://www.exploit-db.com/exploits/6766

This exploit leverages insecure cookie handling in PokerMax Poker League to bypass authentication by setting the 'ValidUserAdmin' cookie to 'admin'. It allows an attacker to gain administrative access without credentials.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: PokerMax Poker League (version not specified)
No auth needed
Prerequisites: Access to the target site's login page · Knowledge of the administrator username (default: 'admin')
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32312
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45931
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6766
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4431
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31784

Scores

EPSS 0.0265
EPSS Percentile 83.7%

Details

CWE
CWE-264
Status published
Products (1)
steve_dawson/pokermax_poker_league_tournament_script 0.13
Published Oct 18, 2008
Tracked Since Feb 18, 2026