CVE-2007-5060
XCMS - Cross-Site Request Forgery via Password Change Functionality
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5060. PoCs published by x0kster.
AI-analyzed exploit summary This exploit leverages an arbitrary command execution vulnerability in Xcms by manipulating the password change functionality. The PoC provides a form that submits malicious input to execute arbitrary PHP code on the target system.
Description
Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain password_ and rpassword_ parameters, possibly related to timestamp values.
Exploits (1)
This exploit leverages an arbitrary command execution vulnerability in Xcms by manipulating the password change functionality. The PoC provides a form that submits malicious input to execute arbitrary PHP code on the target system.