CVE-2007-5374
LightBlog 8.4.1.1 - Authenticated Privilege Escalation via cp_memberedit.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5374. PoCs published by BlackHawk.
AI-analyzed exploit summary This exploit targets LightBlog 8.4.1.1, leveraging an authentication bypass and arbitrary file upload vulnerability to achieve remote code execution. It automates user creation, privilege escalation, and shell upload via crafted HTTP requests.
Description
cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.
Exploits (1)
This exploit targets LightBlog 8.4.1.1, leveraging an authentication bypass and arbitrary file upload vulnerability to achieve remote code execution. It automates user creation, privilege escalation, and shell upload via crafted HTTP requests.