CVE-2008-1783
Prozilla Reviews 1.0 - Unauthenticated Arbitrary User Deletion via UserID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1783. PoCs published by t0pP8uZz.
AI-analyzed exploit summary The exploit describes an arbitrary user deletion vulnerability in Prozilla Reviews Script 1.0 due to improper session handling and lack of admin checks in the DeleteUser.php endpoint. It includes a manual URL-based exploit and a Perl script to automate deletion of all users.
Description
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php.
Exploits (1)
The exploit describes an arbitrary user deletion vulnerability in Prozilla Reviews Script 1.0 due to improper session handling and lack of admin checks in the DeleteUser.php endpoint. It includes a manual URL-based exploit and a Perl script to automate deletion of all users.