CVE-2007-0760
EQdkp <= 1.3.1 - Unauthenticated Account Access via HTTP Referer Spoofing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0760. PoCs published by Eight10.
AI-analyzed exploit summary This exploit describes a referer spoofing vulnerability in EQdkp <= 1.3.1, allowing unauthorized access to a MySQL backup/restore tool. Attackers can download sensitive SQL data, including hashed passwords, and potentially modify the database to gain administrative access.
Description
EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer.
Exploits (1)
This exploit describes a referer spoofing vulnerability in EQdkp <= 1.3.1, allowing unauthorized access to a MySQL backup/restore tool. Attackers can download sensitive SQL data, including hashed passwords, and potentially modify the database to gain administrative access.