CVE-2007-1432

Grayscale Blog 0.8.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-1432.

AI-analyzed exploit summary This advisory details multiple vulnerabilities in Grayscale Blog 0.8.0, including an authentication bypass via unsanitized user input in PHP scripts, XSS in comment fields, and potential SQL injection in various files. The analysis includes code snippets and exploitation examples.

Description

Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the user_permissions parameter to add_users.php, and unspecified parameters to (2) addblog.php, (3) editblog.php, (4) editlinks.php, (5) edit_users.php, and (6) add_links.php.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/3447

This advisory details multiple vulnerabilities in Grayscale Blog 0.8.0, including an authentication bypass via unsanitized user input in PHP scripts, XSS in comment fields, and potential SQL injection in various files. The analysis includes code snippets and exploitation examples.

Classification
Writeup 90%
Attack Type
Auth Bypass | Xss | Sqli
Complexity
Trivial
Reliability
Reliable
Target: Grayscale Blog 0.8.0
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0916
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2417
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/462441/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22911

Scores

EPSS 0.0229
EPSS Percentile 81.0%

Details

Status published
Products (1)
grayscale/grayscale_blog < 0.8.0
Published Mar 13, 2007
Tracked Since Feb 18, 2026