CVE-2008-0350
evilsentinel < 1.0.9 - Unauthenticated Privilege Escalation via admin/index.php Redirect Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0350. PoCs published by BlackHawk.
AI-analyzed exploit summary This exploit bypasses authentication and CAPTCHA in Evilsentinel <= 1.0.9 by directly sending a crafted POST request to disable security filters and change the admin email. It leverages improper session validation and missing CAPTCHA enforcement.
Description
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.
Exploits (1)
This exploit bypasses authentication and CAPTCHA in Evilsentinel <= 1.0.9 by directly sending a crafted POST request to disable security filters and change the admin email. It leverages improper session validation and missing CAPTCHA enforcement.