CVE-2008-6864
Absolute Live Support .NET 5.1 - Unauthenticated Authentication Bypass via Cookie Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6864. PoCs published by Hakxer.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie handling vulnerability in Absolute Live Support, allowing an attacker to bypass authentication by setting a crafted cookie via JavaScript. The exploit grants admin privileges by manipulating the 'xlaALSDEMOadmin' cookie.
Description
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
Exploits (1)
This exploit demonstrates an insecure cookie handling vulnerability in Absolute Live Support, allowing an attacker to bypass authentication by setting a crafted cookie via JavaScript. The exploit grants admin privileges by manipulating the 'xlaALSDEMOadmin' cookie.