CVE-2008-6714
xeCMS <= 1.0.0 RC2 - Unauthenticated Authentication Bypass via xecms_username Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6714. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie handling vulnerability in xeCMS <= 1.0.0 RC2, allowing an attacker to bypass authentication by setting arbitrary admin cookies via JavaScript. The PoC provides a simple JavaScript snippet to set the required cookies and gain admin access.
Description
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username cookie.
Exploits (1)
This exploit demonstrates an insecure cookie handling vulnerability in xeCMS <= 1.0.0 RC2, allowing an attacker to bypass authentication by setting arbitrary admin cookies via JavaScript. The PoC provides a simple JavaScript snippet to set the required cookies and gain admin access.