CVE-2007-4937
CS Guestbook - Unauthenticated Sensitive Information Exposure via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4937. PoCs published by Cr@zy_King.
AI-analyzed exploit summary The provided text describes an information-disclosure vulnerability in CS-Guestbook, where sensitive information can be accessed via a specific URL path. No actual exploit code is present, only a description and example URL.
Description
CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php.
Exploits (1)
The provided text describes an information-disclosure vulnerability in CS-Guestbook, where sensitive information can be accessed via a specific URL path. No actual exploit code is present, only a description and example URL.