Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2775. PoCs published by BlackHawk.
AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in AlstraSoft Live Support v1.21 due to missing exit() after header() in common.php, allowing retrieval of admin credentials without authentication.
Description
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php.
Exploits (1)
This exploit leverages an authentication bypass vulnerability in AlstraSoft Live Support v1.21 due to missing exit() after header() in common.php, allowing retrieval of admin credentials without authentication.