CVE-2009-4808
Graugon PHP Article Publisher 1.0 - Unauthenticated Authentication Bypass via g_admin Cookie
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-4808. PoCs published by x0r, ZoRLu.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 via the 'c' and 'id' parameters, as well as insecure cookie handling for authentication bypass. The PoC includes URLs to extract sensitive data from the database and a JavaScript snippet to set an admin cookie.
Description
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1.
Exploits (2)
The exploit demonstrates SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 via the 'c' and 'id' parameters, as well as insecure cookie handling for authentication bypass. The PoC includes URLs to extract sensitive data from the database and a JavaScript snippet to set an admin cookie.
This exploit demonstrates insecure cookie handling in Article Publisher PRO 1.5, allowing an attacker to bypass authentication by setting arbitrary cookie values for admin or user sessions.