CVE-2007-1480
Creative Guestbook 1.0 - Unauthenticated Administrative Account Creation via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1480. PoCs published by Dj7xpl.
AI-analyzed exploit summary This exploit demonstrates two vulnerabilities in Creative Guestbook 1.0: a stored XSS vulnerability in the guestbook entry field and an unauthorized admin user creation flaw via direct POST requests to createadmin.php. The PoC includes HTML forms and endpoints to trigger both issues.
Description
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.
Exploits (1)
This exploit demonstrates two vulnerabilities in Creative Guestbook 1.0: a stored XSS vulnerability in the guestbook entry field and an unauthorized admin user creation flaw via direct POST requests to createadmin.php. The PoC includes HTML forms and endpoints to trigger both issues.