Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-5412. PoCs published by nuffsaid.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Easynews <= 4.4.1 by manipulating the `en_login_id` parameter to bypass the admin login check. It allows unauthorized access to admin functionalities, including editing PHP files.
Description
admin.php in PHP Outburst Easynews 4.4.1 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication, and gain the ability to execute arbitrary code, via the en_login_id parameter.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Easynews <= 4.4.1 by manipulating the `en_login_id` parameter to bypass the admin login check. It allows unauthorized access to admin functionalities, including editing PHP files.