CVE-2007-4047
geoblog 1 - Unauthenticated Arbitrary Comment and Blog Deletion via Admin Endpoints
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-4047. PoCs published by joseph.giron13.
AI-analyzed exploit summary The provided text describes an authentication bypass vulnerability in geoBlog v1, allowing unauthorized deletion of blogs and comments via direct URL manipulation. No actual exploit code is present, only a description and example URL.
Description
geoBlog (aka BitDamaged) 1 does not require authentication for (1) deletecomment.php, (2) deleteblog.php, and (3) listcomment.php in admin/, which allows remote attackers to delete arbitrary comments, delete arbitrary blogs, and have other unspecified impact via a request with a valid id parameter.
Exploits (2)
The provided text describes an authentication bypass vulnerability in geoBlog v1, allowing unauthorized deletion of blogs and comments via direct URL manipulation. No actual exploit code is present, only a description and example URL.
The provided text describes an authentication bypass vulnerability in geoBlog v1, allowing unauthorized deletion of blogs and comments via direct URL manipulation. No actual exploit code is present, only a description and example URL.