cve/2014/CVE-2014-8686.md
2024-05-26 14:27:05 +02:00

852 B

CVE-2014-8686

Description

CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.

POC

Reference

Github

No PoCs found on GitHub currently.