Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1567. PoCs published by CHT Security Research.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in a PHP-based application by injecting an administrator-level value into the database through a hidden form field. The exploit leverages improper input validation to escalate privileges.
Description
profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in a PHP-based application by injecting an administrator-level value into the database through a hidden form field. The exploit leverages improper input validation to escalate privileges.