---
cve: "CVE-2008-7024"
severity: "LOW"
cvss: 3.1
epss: "2.5%"
vendor: "n/a"
kev: false
exploited: false
published: "2009-08-21 14:30:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T08:12:21+02:00"
---

# CVE-2008-7024

> 3.1 LOW · 🧪 PoC

## Beschreibung

admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users."

## Exploit-Evidenz

- [EDB-6584 — The Gemini Portal 4.7 - Insecure Cookie Handling](https://www.exploit-db.com/exploits/6584) ✅

## Referenzen

- <http://www.securityfocus.com/bid/31429>
- <https://www.exploit-db.com/exploits/6584>
- <http://secunia.com/advisories/32057>
- <http://www.securityfocus.com/archive/1/496761/100/0/threaded>
- <http://osvdb.org/48639>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/45439>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2008-7024) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
