CVE-2008-6919
TaskDriver < 1.3 - Unauthenticated Authentication Bypass via Auth Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6919. PoCs published by cOndemned.
AI-analyzed exploit summary This exploit leverages insecure cookie handling in TaskDriver <= 1.3 to bypass authentication by setting the 'auth' cookie to 'fook!admin', allowing an attacker to change the admin password via a POST request to profileedit.php.
Description
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."
Exploits (1)
This exploit leverages insecure cookie handling in TaskDriver <= 1.3 to bypass authentication by setting the 'auth' cookie to 'fook!admin', allowing an attacker to change the admin password via a POST request to profileedit.php.