CVE-2008-6667
A+ PHP Scripts News Management System - Unauthenticated Authentication Bypass via Cookie Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6667. PoCs published by Virangar Security.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie handling vulnerability in A+ PHP Scripts - News Management System. By setting specific cookie values via JavaScript, an attacker can bypass authentication and gain admin access.
Description
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.
Exploits (1)
This exploit demonstrates an insecure cookie handling vulnerability in A+ PHP Scripts - News Management System. By setting specific cookie values via JavaScript, an attacker can bypass authentication and gain admin access.