CVE-2008-6300

GWM Galatolo Webmanager - Authentication Bypass

Title source: rule

Description

Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Virangar Security · textwebappsphp
https://www.exploit-db.com/exploits/6081

Scores

EPSS 0.0173
EPSS Percentile 82.3%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

gwm/galatolo_webmanager

Timeline

Published Feb 26, 2009
Tracked Since Feb 18, 2026