CVE-2008-6553
Micro CMS 0.3.5 - Unauthenticated Administrative Account Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6553. PoCs published by StAkeR.
AI-analyzed exploit summary This Perl script exploits an authentication bypass vulnerability in Micro CMS <= 0.3.5, allowing unauthorized addition, deletion, or password changes for admin accounts via crafted POST requests to 'microcms-admin-home.php'.
Description
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove administrative accounts via a delete_admin action, and (3) modify administrative passwords via a change_password action.
Exploits (1)
This Perl script exploits an authentication bypass vulnerability in Micro CMS <= 0.3.5, allowing unauthorized addition, deletion, or password changes for admin accounts via crafted POST requests to 'microcms-admin-home.php'.