CVE-2007-6490
Falcon Series One CMS 1.4.3 - Cross-Site Request Forgery via Password Change Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6490. PoCs published by MhZ91.
AI-analyzed exploit summary The exploit demonstrates multiple remote file inclusion (RFI) vulnerabilities in Falcon CMS, allowing arbitrary code execution via manipulated 'dir[classes]' and 'error' parameters. It also includes a permanent XSS and CSRF exploit for password change.
Description
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php.
Exploits (1)
The exploit demonstrates multiple remote file inclusion (RFI) vulnerabilities in Falcon CMS, allowing arbitrary code execution via manipulated 'dir[classes]' and 'error' parameters. It also includes a permanent XSS and CSRF exploit for password change.