CVE-2006-6773

Fishyshoop 0.930 beta - Unauthenticated Arbitrary Admin User Creation via is_admin Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6773. PoCs published by James Gray.

AI-analyzed exploit summary This exploit leverages an insecure registration process in Fishyshoop to create an admin account by directly submitting a POST request with admin privileges. It bypasses proper authentication checks by setting 'is_admin=1' in the form data.

Description

pages/register/register.php in Fishyshoop 0.930 beta allows remote attackers to create arbitrary administrative users by setting the is_admin HTTP POST parameter to 1.

Exploits (1)

exploitdb WORKING POC VERIFIED
by James Gray · perlwebappsphp
https://www.exploit-db.com/exploits/3011

This exploit leverages an insecure registration process in Fishyshoop to create an admin account by directly submitting a POST request with admin privileges. It bypasses proper authentication checks by setting 'is_admin=1' in the form data.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Fishyshoop (version unspecified)
No auth needed
Prerequisites: Access to the Fishyshoop registration endpoint · Perl with WWW::Curl::Easy module installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/455260/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2077
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21731
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23490
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/5182

Scores

EPSS 0.0243
EPSS Percentile 82.1%

Details

Status published
Products (1)
fishyshoop/fishyshoop 0.930_beta
Published Dec 27, 2006
Tracked Since Feb 18, 2026