CVE-2008-4784
aflog 1.01 - Unauthenticated Authentication Bypass via aflog_auth_a Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4784. PoCs published by JosS.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in aflog 1.01 by manipulating insecure cookie handling. The attacker sets the 'aflog_auth_a' cookie to 'A' to gain admin access to restricted pages like /edit_delete.php.
Description
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in aflog 1.01 by manipulating insecure cookie handling. The attacker sets the 'aflog_auth_a' cookie to 'A' to gain admin access to restricted pages like /edit_delete.php.