CVE-2008-6804
Tribiq CMS 5.0.9a beta - Unauthenticated Authentication Bypass via Cookie Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6804. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates insecure cookie handling in biqcms 5.0.9a (beta), allowing an attacker to set arbitrary admin cookies via JavaScript, potentially leading to authentication bypass.
Description
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue
Exploits (1)
This exploit demonstrates insecure cookie handling in biqcms 5.0.9a (beta), allowing an attacker to set arbitrary admin cookies via JavaScript, potentially leading to authentication bypass.