CVE-2009-1587
PHP Site Lock 2.0 - Unauthenticated Authentication Bypass via Cookie Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1587. PoCs published by ThE g0bL!N.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie handling vulnerability in PHP Site Lock 2.0, allowing an attacker to bypass authentication by setting arbitrary cookie values to escalate privileges to admin.
Description
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values.
Exploits (1)
This exploit demonstrates an insecure cookie handling vulnerability in PHP Site Lock 2.0, allowing an attacker to bypass authentication by setting arbitrary cookie values to escalate privileges to admin.