CVE-2007-5913

JBC Explorer < 7.20_rc1 - Unauthenticated Authentication Bypass via auth.php Parameter Manipulation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-5913. PoCs published by DarkFig.

AI-analyzed exploit summary This exploit targets JBC Explorer <= V7.20 RC 1, leveraging a remote code execution vulnerability by manipulating configuration files and injecting malicious PHP code. It establishes an interactive shell by exploiting improper input validation in the application.

Description

dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkFig · phpwebappsphp
https://www.exploit-db.com/exploits/4608

This exploit targets JBC Explorer <= V7.20 RC 1, leveraging a remote code execution vulnerability by manipulating configuration files and injecting malicious PHP code. It establishes an interactive shell by exploiting improper input validation in the application.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: JBC Explorer <= V7.20 RC 1
No auth needed
Prerequisites: Network access to the target application · PHP environment to run the exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27533
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38269
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/42069
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26332
Various Sources x_refsource_misc
http://mgsdl.free.fr/?1:33
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/483268/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3358
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4608

Scores

EPSS 0.0726
EPSS Percentile 93.5%

Details

CWE
CWE-287
Status published
Products (1)
jean_charles/jbc_explorer < 7.20_rc1
Published Nov 10, 2007
Tracked Since Feb 18, 2026