CVE-2008-6231 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 87)
Patch early
A public exploit exists.
Description
Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.91% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-255 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-02-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| preprojects | pre classified listings |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Pre Shopping Mall - Insecure Cookie Handling | 2008-11-05 |
| exploit-db | Pre Classified Listings - Insecure Cookie Handling | 2008-11-05 |
References
- http://secunia.com/advisories/32557
- http://www.securityfocus.com/bid/32126
- http://www.vupen.com/english/advisories/2008/3019
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46390
- https://www.exploit-db.com/exploits/7000
- http://secunia.com/advisories/32557
- http://www.securityfocus.com/bid/32126
- http://www.vupen.com/english/advisories/2008/3019
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46390
- https://www.exploit-db.com/exploits/7000
→ the Explorer · watch your stack · NVD