20121108 Vulnerability Report on AWCM 2.2mailing list
http://archives.neohapsis.com/archives/bugtraq/2012-11/0039.html CVE-2012-2437
AR Web Content Manager (AWCM) - 'cookie_gen.php' Arbitrary Cookie Generation
Record summary
CVE-2012-2437 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAR Web Content Manager (AWCM) - 'cookie_gen.php' Arbitrary Cookie GenerationExploitDB exploitby Sooel SonNot analyzed1 file
References
4packetstormsecurity.org
http://packetstormsecurity.org/files/117975/AWCM-2.2-Access-Bypass.html awcm-cookie-sec-bypass(79926)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/79926 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-2437