CVE-2007-2001
crea-book < 1.0 - Authenticated PHP Code Injection via Admin Configuration Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2001. PoCs published by Xst3nZ.
AI-analyzed exploit summary This is a detailed technical analysis of CVE-2007-2000, covering SQL injection for admin bypass and PHP code execution weaknesses in Crea-Book <= 1.0. It includes proof-of-concept steps and root cause analysis.
Description
Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified fields, which injects into config.inc.php3.
Exploits (1)
This is a detailed technical analysis of CVE-2007-2000, covering SQL injection for admin bypass and PHP code execution weaknesses in Crea-Book <= 1.0. It includes proof-of-concept steps and root cause analysis.