CVE-2008-7179
OTManager CMS 2.4 - Auth Bypass
Title source: llmDescription
OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADMIN_Nome cookies to certain values, as reachable in Admin/index.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Virangar Security · textwebappsphp
https://www.exploit-db.com/exploits/5959
Scores
EPSS
0.0106
EPSS Percentile
77.5%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
otmanager/otmanager_cms
Timeline
Published
Sep 08, 2009
Tracked Since
Feb 18, 2026