EIP-2026-112036
PRE-CVEShorty 0.7.1b - (Authentication Bypass) Insecure Cookie Handling
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112036. PoCs published by Pedro Laguna.
AI-analyzed exploit summary The exploit demonstrates an authentication bypass vulnerability in Shorty v0.7.1 Beta by setting a specific cookie value ('snickerdoodle=polarbears') to bypass the login mechanism. The vulnerability lies in the hardcoded cookie check in the 'authenticate()' and 'verify()' functions.
Description
Shorty 0.7.1b - (Authentication Bypass) Insecure Cookie Handling
Exploits (1)
The exploit demonstrates an authentication bypass vulnerability in Shorty v0.7.1 Beta by setting a specific cookie value ('snickerdoodle=polarbears') to bypass the login mechanism. The vulnerability lies in the hardcoded cookie check in the 'authenticate()' and 'verify()' functions.