CVE-2007-6398
Flat PHP Board < 1.2 - Unauthenticated Authentication Bypass via fpb_username Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6398. PoCs published by KiNgOfThEwOrLd.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Flat PHP Board <= 1.2, including remote command execution via file upload, directory traversal, and credential disclosure. It provides functional PoC code for RCE by injecting PHP code into user registration fields.
Description
Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrary user account via the fpb_username cookie.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Flat PHP Board <= 1.2, including remote command execution via file upload, directory traversal, and credential disclosure. It provides functional PoC code for RCE by injecting PHP code into user registration fields.