CVE-2003-1488
Truegalerie 1.0 - Unauthenticated Administrator Access via Admin Parameter Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1488. PoCs published by frog.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Truegalerie by manipulating the 'loggedin' URI parameter to gain unauthorized administrative access. The attack is trivial and relies on insufficient input validation.
Description
The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Truegalerie by manipulating the 'loggedin' URI parameter to gain unauthorized administrative access. The attack is trivial and relies on insufficient input validation.