CVE-2008-2347

Mypicgallery - Authentication Bypass

Title source: rule

Description

MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin" in a direct request to admin/addUser.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by t0pP8uZz · perlwebappsphp
https://www.exploit-db.com/exploits/5650

Scores

EPSS 0.0226
EPSS Percentile 84.4%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

mypicgallery/mypicgallery

Timeline

Published May 20, 2008
Tracked Since Feb 18, 2026