CVE-2002-1560

gBook 1.4 - Unauthenticated Authentication Bypass via Login Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1560. PoCs published by frog.

AI-analyzed exploit summary The exploit describes an authentication bypass vulnerability in gBook v1.4, where an attacker can gain administrative access by passing a specific parameter in the URL. This allows unauthorized execution of administrative actions.

Description

index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.

Exploits (1)

exploitdb WRITEUP VERIFIED
by frog · textwebappsphp
https://www.exploit-db.com/exploits/21960

The exploit describes an authentication bypass vulnerability in gBook v1.4, where an attacker can gain administrative access by passing a specific parameter in the URL. This allows unauthorized execution of administrative actions.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: gBook v1.4
No auth needed
Prerequisites: Access to the target URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-10/0328.html
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10455.php
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6033

Scores

EPSS 0.1032
EPSS Percentile 95.1%

Details

Status published
Products (1)
martin_bauer/gbook 1.4
Published Mar 31, 2003
Tracked Since Feb 18, 2026