CVE-2007-6234
FTP Admin 0.1.0 - Unauthenticated Authentication Bypass via Loggedin Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6234. PoCs published by Omni.
AI-analyzed exploit summary The document describes multiple vulnerabilities in FTP Admin v0.1.0, including XSS, Local File Inclusion, and Admin Bypass. It provides PoC URLs but lacks executable exploit code.
Description
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Omni · textwebappsphp
https://www.exploit-db.com/exploits/4681
The document describes multiple vulnerabilities in FTP Admin v0.1.0, including XSS, Local File Inclusion, and Admin Bypass. It provides PoC URLs but lacks executable exploit code.
Classification
Writeup 90%
Attack Type
Xss | Info Leak | Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target:
FTP Admin v0.1.0
No auth needed
Prerequisites:
Access to the web interface · Register globals enabled for LFI
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38782
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/4681
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/27875
Scores
EPSS
0.0427
EPSS Percentile
89.8%
Details
CWE
CWE-287
Status
published
Products (1)
ftp_admin/ftp_admin
0.1.0
Published
Dec 04, 2007
Tracked Since
Feb 18, 2026