CVE-2012-2437: Awcm-CMS Ar Web Content Manager

Medium severity, CVSS 5.0. EPSS: 2.4% chance of exploitation in the next 30 days.

cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.

Affected products

  • Awcm-CMS Ar Web Content Manager: version 2.2 only

Published 2012-11-26. Last modified 2026-06-16.