CVE-2009-1619

Teraway FileStream 1.0 - Unauthenticated Authentication Bypass via twFSadmin Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1619. PoCs published by ThE g0bL!N.

AI-analyzed exploit summary This exploit leverages insecure cookie handling in Teraway FileStream 1.0 by setting a JavaScript cookie to bypass authentication. Accessing the menu page after setting the cookie grants administrative privileges.

Description

Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ThE g0bL!N · textwebappsphp
https://www.exploit-db.com/exploits/8551

This exploit leverages insecure cookie handling in Teraway FileStream 1.0 by setting a JavaScript cookie to bypass authentication. Accessing the menu page after setting the cookie grants administrative privileges.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Teraway FileStream 1.0
No auth needed
Prerequisites: Victim must visit a malicious link or have JavaScript execution in their browser context
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34818
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8551
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34735

Scores

EPSS 0.0254
EPSS Percentile 82.9%

Details

CWE
CWE-287
Status published
Products (1)
teraway/filestream 1.0
Published May 12, 2009
Tracked Since Feb 18, 2026