CVE-2008-6855
Xigla Absolute News Feed 1.0 and possibly 1.5 - Unauthenticated Authentication Bypass via Cookie Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6855. PoCs published by Hakxer.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie vulnerability in Absolute News Feed, allowing an attacker to set an admin cookie via JavaScript and bypass authentication. The PoC involves executing a JavaScript snippet to manipulate the cookie and gain unauthorized access.
Description
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.
Exploits (1)
This exploit demonstrates an insecure cookie vulnerability in Absolute News Feed, allowing an attacker to set an admin cookie via JavaScript and bypass authentication. The PoC involves executing a JavaScript snippet to manipulate the cookie and gain unauthorized access.