CVE-2008-7179

OTManager CMS 2.4 - Unauthenticated Authentication Bypass via Cookie Manipulation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-7179. PoCs published by Virangar Security.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in OTManager CMS v2.4 by crafting malicious cookies to gain admin access without credentials. The vulnerability arises from insecure cookie handling in the admin login process.

Description

OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADMIN_Nome cookies to certain values, as reachable in Admin/index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Virangar Security · textwebappsphp
https://www.exploit-db.com/exploits/5959

This exploit demonstrates an authentication bypass vulnerability in OTManager CMS v2.4 by crafting malicious cookies to gain admin access without credentials. The vulnerability arises from insecure cookie handling in the admin login process.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: OTManager CMS v2.4
No auth needed
Prerequisites: Access to the target's admin login page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29999
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5959

Scores

EPSS 0.0229
EPSS Percentile 80.9%

Details

CWE
CWE-287
Status published
Products (1)
otmanager/otmanager_cms 2.4
Published Sep 08, 2009
Tracked Since Feb 18, 2026