CVE-2007-0760

EQdkp <= 1.3.1 - Unauthenticated Account Access via HTTP Referer Spoofing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-0760. PoCs published by Eight10.

AI-analyzed exploit summary This exploit describes a referer spoofing vulnerability in EQdkp <= 1.3.1, allowing unauthorized access to a MySQL backup/restore tool. Attackers can download sensitive SQL data, including hashed passwords, and potentially modify the database to gain administrative access.

Description

EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Eight10 · textwebappsphp
https://www.exploit-db.com/exploits/3252

This exploit describes a referer spoofing vulnerability in EQdkp <= 1.3.1, allowing unauthorized access to a MySQL backup/restore tool. Attackers can download sensitive SQL data, including hashed passwords, and potentially modify the database to gain administrative access.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: EQdkp <= 1.3.1
No auth needed
Prerequisites: Referer spoofing tool · Access to the target EQdkp admin backup URL
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/32152
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24038
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3252
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/33112
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20805

Scores

EPSS 0.0241
EPSS Percentile 82.4%

Details

Status published
Products (1)
eqdkp/eqdkp 1.3.1
Published Feb 06, 2007
Tracked Since Feb 18, 2026