Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2776. PoCs published by BlackHawk.
AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in AlstraSoft Template Seller Pro <= 3.25 by injecting session variables via URL parameters to change the admin password without proper authentication.
Description
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php.
Exploits (1)
This exploit leverages an authentication bypass vulnerability in AlstraSoft Template Seller Pro <= 3.25 by injecting session variables via URL parameters to change the admin password without proper authentication.