Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-0518. PoCs published by Milos Zivanovic.
AI-analyzed exploit summary This writeup describes two information disclosure vulnerabilities in Smart PHP Subscriber, where admin passwords and subscriber lists are stored in weakly encoded files. It includes a PHP script to decode the admin password.
Description
Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.
Exploits (1)
This writeup describes two information disclosure vulnerabilities in Smart PHP Subscriber, where admin passwords and subscriber lists are stored in weakly encoded files. It includes a PHP script to decode the admin password.