EIP-2026-108985
PRE-CVEKemana Directory 1.5.6 - 'qvc_init()' Cookie Poisoning CAPTCHA Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108985. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a CAPTCHA bypass vulnerability in Kemana Directory 1.5.6 by poisoning the 'qvc_value' cookie with a SHA1 hash. It uses Perl to automate the process of sending requests, extracting the cookie, and replacing it with a crafted value to bypass authentication.
Description
Kemana Directory 1.5.6 - 'qvc_init()' Cookie Poisoning CAPTCHA Bypass
Exploits (1)
This exploit demonstrates a CAPTCHA bypass vulnerability in Kemana Directory 1.5.6 by poisoning the 'qvc_value' cookie with a SHA1 hash. It uses Perl to automate the process of sending requests, extracting the cookie, and replacing it with a crafted value to bypass authentication.