CVE-2006-4782
WebSPELL <= 4.01.01 - Authentication Bypass and Information Disclosure via userID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4782. PoCs published by Trex.
AI-analyzed exploit summary This exploit targets WebSPELL <= 4.01.01 by leveraging an accessible database backup download vulnerability. The exploit allows unauthorized access to database backups via a direct URL request.
Description
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain sensitive information stored in the database via a modified userID parameter in a write action to admin/database.php.
Exploits (1)
This exploit targets WebSPELL <= 4.01.01 by leveraging an accessible database backup download vulnerability. The exploit allows unauthorized access to database backups via a direct URL request.