CVE-2006-2527
phpBazar 2.1.0 - Unauthenticated Authentication Bypass via Action Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2527.
AI-analyzed exploit summary The exploit demonstrates a remote file inclusion vulnerability in phpBazar <= 2.1.0, allowing arbitrary code execution via a malicious URL parameter. It also includes an admin credential access vector through direct parameter manipulation.
Description
Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the administrative section by setting the action parameter to edit_member and the value parameter to 1.
Exploits (1)
The exploit demonstrates a remote file inclusion vulnerability in phpBazar <= 2.1.0, allowing arbitrary code execution via a malicious URL parameter. It also includes an admin credential access vector through direct parameter manipulation.