EIP-2026-111678

PRE-CVE

Rapidsendit Clone Script - 'admin.php' Insecure Cookie Authentication Bypass

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111678. PoCs published by NoGe.

AI-analyzed exploit summary The exploit demonstrates an authentication bypass vulnerability in Rapidsendit Clone Script by setting a specific cookie value to gain administrative access. The cookie 'logged' is set to a hardcoded MD5 hash representing the password, bypassing proper authentication mechanisms.

Description

Rapidsendit Clone Script - 'admin.php' Insecure Cookie Authentication Bypass

Exploits (1)

exploitdb WORKING POC VERIFIED
by NoGe · textwebappsphp
https://www.exploit-db.com/exploits/34808

The exploit demonstrates an authentication bypass vulnerability in Rapidsendit Clone Script by setting a specific cookie value to gain administrative access. The cookie 'logged' is set to a hardcoded MD5 hash representing the password, bypassing proper authentication mechanisms.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Rapidsendit Clone Script 2.1 and prior
No auth needed
Prerequisites: Access to the target application's login page · Ability to execute JavaScript in the context of the target domain
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026