CVE-2008-6296

Maran Php Shop - Access Control

Title source: rule
STIX 2.1

Description

admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."

Exploits (1)

exploitdb WORKING POC VERIFIED
by JosS · textwebappsphp
https://www.exploit-db.com/exploits/6954

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46306
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6954
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32048

Scores

EPSS 0.0226
EPSS Percentile 84.7%

Details

CWE
CWE-264
Status published
Products (1)
maran/php_shop
Published Feb 26, 2009
Tracked Since Feb 18, 2026