CVE-2008-2488
RoomPHPlanning 1.5 - Authenticated Privilege Escalation via admin/userform.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2488. PoCs published by Stack.
AI-analyzed exploit summary This exploit demonstrates an arbitrary admin user addition vulnerability in RoomPHPlanning v1.5 by submitting a crafted POST request to userform.php. The exploit allows an attacker to create an admin account without authentication.
Description
admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts.
Exploits (1)
This exploit demonstrates an arbitrary admin user addition vulnerability in RoomPHPlanning v1.5 by submitting a crafted POST request to userform.php. The exploit allows an attacker to create an admin account without authentication.