cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.
- http://packetstormsecurity.org/files/117975/AWCM-2.2-Access-Bypass.html
No PoCs found on GitHub currently.