CVE-2008-5873

Yerba SACphp < 6.3 - Unauthenticated Authentication Bypass via galleta[sesion] Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-5873. PoCs published by StAkeR.

AI-analyzed exploit summary This is a writeup detailing multiple vulnerabilities in Yerba SACphp <= 6.3, including admin login bypass, privilege escalation, arbitrary database download, and arbitrary admin addition via crafted SID parameters. No executable exploit code is provided.

Description

Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a value beginning with 1:1: followed by a username.

Exploits (1)

exploitdb WRITEUP VERIFIED
by StAkeR · textwebappsphp
https://www.exploit-db.com/exploits/6691

This is a writeup detailing multiple vulnerabilities in Yerba SACphp <= 6.3, including admin login bypass, privilege escalation, arbitrary database download, and arbitrary admin addition via crafted SID parameters. No executable exploit code is provided.

Classification
Writeup 90%
Attack Type
Auth Bypass | Info Leak | Other
Complexity
Trivial
Reliability
Theoretical
Target: Yerba SACphp <= 6.3
No auth needed
Prerequisites: access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32093
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31619
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6691
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45734
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4883

Scores

EPSS 0.0265
EPSS Percentile 83.6%

Details

CWE
CWE-264
Status published
Products (2)
yerba/yerba 6.28
yerba/yerba < 6.3
Published Jan 08, 2009
Tracked Since Feb 18, 2026