CVE-2008-6293

Accscripts Acc Real Estate - Access Control

Title source: rule

Description

admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."

Exploits (3)

exploitdb WORKING POC VERIFIED
by Hakxer · textwebappsphp
https://www.exploit-db.com/exploits/6964
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/6965
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/6968

Scores

EPSS 0.0368
EPSS Percentile 88.0%

Details

CWE
CWE-264
Status published
Products (1)
accscripts/acc_real_estate 4.0
Published Feb 26, 2009
Tracked Since Feb 18, 2026