CVE-2009-2117
phPortal 1.0 - Unauthenticated Authentication Bypass via kulladi Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2117. PoCs published by KnocKout.
AI-analyzed exploit summary This exploit leverages insecure cookie handling in PhpPortal v1 to manipulate the 'kulladi' cookie, allowing an attacker to bypass authentication by setting an arbitrary username. The exploit is executed via JavaScript to set the cookie and then navigating to the user panel page.
Description
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username.
Exploits (1)
This exploit leverages insecure cookie handling in PhpPortal v1 to manipulate the 'kulladi' cookie, allowing an attacker to bypass authentication by setting an arbitrary username. The exploit is executed via JavaScript to set the cookie and then navigating to the user panel page.