Record summary

CVE-2012-2437 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBAR Web Content Manager (AWCM) - 'cookie_gen.php' Arbitrary Cookie GenerationExploitDB exploitby Sooel SonNot analyzed1 file
ExploitDB

PoC details

References

4