CVE-2008-0391
Alilg Alitalk - Authentication Bypass
Title source: ruleDescription
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by tomplixsee · textwebappsphp
https://www.exploit-db.com/exploits/4922
Scores
EPSS
0.0471
EPSS Percentile
89.2%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
alilg/alitalk
Timeline
Published
Jan 23, 2008
Tracked Since
Feb 18, 2026