CVE-2008-1971

phShoutBox Final <1.5 - Privilege Escalation

Title source: llm

Description

phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by t0pP8uZz · textwebappsphp
https://www.exploit-db.com/exploits/5467

Scores

EPSS 0.0472
EPSS Percentile 89.2%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

phphq/phshoutbox_final < 1.5

Timeline

Published Apr 27, 2008
Tracked Since Feb 18, 2026