Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2382. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie handling vulnerability in phpMyBlockchecker 1.0.0055, allowing an attacker to bypass authentication by setting a specific cookie value. The PoC uses JavaScript to set the 'PHPMYBCAdmin' cookie to 'LOGGEDIN', granting unauthorized access to the admin panel.
Description
admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin cookie to LOGGEDIN.
Exploits (1)
This exploit demonstrates an insecure cookie handling vulnerability in phpMyBlockchecker 1.0.0055, allowing an attacker to bypass authentication by setting a specific cookie value. The PoC uses JavaScript to set the 'PHPMYBCAdmin' cookie to 'LOGGEDIN', granting unauthorized access to the admin panel.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H