peter bassill · operator
$ cve CVE-2008-7027 JSON

CVE-2008-7027 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.29% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2009-08-21
Last modified2026-06-16

Affected (1)

VendorProduct
libra file managerphp filemanager

Public exploits

SourceTitleDate
exploit-dbLibra PHP File Manager 1.18 - Insecure Cookie Handling2008-09-26

References

→ the Explorer  ·  watch your stack  ·  NVD