CVE-2009-4546
Logoshows BBS 2.0 - Authentication Bypass via Cookie Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4546. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Logoshows BBS 2.0 by manipulating cookies to gain admin privileges. The PoC uses JavaScript to set cookies for username and privilege level, allowing unauthorized access.
Description
globepersonnel_login.asp in Logoshows BBS 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) pb_username (aka pb%5Fusername) and (2) level cookies.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Logoshows BBS 2.0 by manipulating cookies to gain admin privileges. The PoC uses JavaScript to set cookies for username and privilege level, allowing unauthorized access.