CVE-2008-0391
aliTalk 1.9.1.1 - Unauthenticated Arbitrary User Account Creation via lilil Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0391. PoCs published by tomplixsee.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in ALITALK v1.9.1.1, including SQL injection, password change bypass, user registration bypass, and admin/user login SQL injection. It provides specific code snippets and example URLs to exploit these vulnerabilities.
Description
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in ALITALK v1.9.1.1, including SQL injection, password change bypass, user registration bypass, and admin/user login SQL injection. It provides specific code snippets and example URLs to exploit these vulnerabilities.