CVE-2009-4671
RoomPHPlanning 1.6 - Unauthenticated Authentication Bypass via Cookie Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4671. PoCs published by ThE g0bL!N.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in RoomPHPlanning v1.6, including SQL injection, authentication bypass, insecure cookie handling, and unauthorized deletion of rooms/users. It provides clear exploitation steps for each vulnerability.
Description
Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cookie to a value associated with the admin account.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in RoomPHPlanning v1.6, including SQL injection, authentication bypass, insecure cookie handling, and unauthorized deletion of rooms/users. It provides clear exploitation steps for each vulnerability.