CVE-2012-2437
ar web content manager 2.2 - Unauthenticated Improper Authentication via cookie_gen.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-2437. PoCs published by Sooel Son.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass and security bypass in AWCM 2.2 via cookie manipulation and form submission. The PoC shows how to set arbitrary cookies and inject comments without proper authorization.
Description
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.
Exploits (1)
This exploit demonstrates an authentication bypass and security bypass in AWCM 2.2 via cookie manipulation and form submission. The PoC shows how to set arbitrary cookies and inject comments without proper authorization.