CVE-2006-1213
JiRo's Banner System Experience and Professional <1.0 - Privilege E...
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1213. PoCs published by nukedx.
AI-analyzed exploit summary This exploit leverages an unauthorized admin addition vulnerability in Jiros Banner Experience Pro by sending a crafted POST request to the 'update.asp' endpoint. It allows an attacker to create an admin account with system privileges without authentication.
Description
JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account.
Exploits (1)
This exploit leverages an unauthorized admin addition vulnerability in Jiros Banner Experience Pro by sending a crafted POST request to the 'update.asp' endpoint. It allows an attacker to create an admin account with system privileges without authentication.