CVE-2009-1619
Teraway FileStream 1.0 - Unauthenticated Authentication Bypass via twFSadmin Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1619. PoCs published by ThE g0bL!N.
AI-analyzed exploit summary This exploit leverages insecure cookie handling in Teraway FileStream 1.0 by setting a JavaScript cookie to bypass authentication. Accessing the menu page after setting the cookie grants administrative privileges.
Description
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by ThE g0bL!N · textwebappsphp
https://www.exploit-db.com/exploits/8551
This exploit leverages insecure cookie handling in Teraway FileStream 1.0 by setting a JavaScript cookie to bypass authentication. Accessing the menu page after setting the cookie grants administrative privileges.
Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
Teraway FileStream 1.0
No auth needed
Prerequisites:
Victim must visit a malicious link or have JavaScript execution in their browser context
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34818
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/8551
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/34735
Scores
EPSS
0.0254
EPSS Percentile
82.9%
Details
CWE
CWE-287
Status
published
Products (1)
teraway/filestream
1.0
Published
May 12, 2009
Tracked Since
Feb 18, 2026