CVE-2008-6859
Absolute Control Panel XE 1.5 - Unauthenticated Authentication Bypass via Cookie Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6859. PoCs published by Hakxer.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie handling vulnerability in Absolute Control Panel XE, allowing an attacker to bypass authentication by setting a malicious cookie via JavaScript. The exploit grants admin access by manipulating the 'xlaCPadmin' cookie.
Description
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
Exploits (1)
This exploit demonstrates an insecure cookie handling vulnerability in Absolute Control Panel XE, allowing an attacker to bypass authentication by setting a malicious cookie via JavaScript. The exploit grants admin access by manipulating the 'xlaCPadmin' cookie.