CVE-2008-7051

AJ Square AJ Article - Unauthenticated Administrator Access via Direct Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-7051. PoCs published by G4N0K.

AI-analyzed exploit summary This is a writeup describing an authentication bypass vulnerability in AJ Article, a commercial PHP script. It lists vulnerable admin endpoints but does not include functional exploit code or technical details.

Description

AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php, and (11) logo.php in admin/.

Exploits (1)

exploitdb WRITEUP VERIFIED
by G4N0K · textwebappsphp
https://www.exploit-db.com/exploits/7081

This is a writeup describing an authentication bypass vulnerability in AJ Article, a commercial PHP script. It lists vulnerable admin endpoints but does not include functional exploit code or technical details.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: AJ Article (version unspecified)
No auth needed
Prerequisites: access to admin endpoints
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3097
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7081
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32254

Scores

EPSS 0.0251
EPSS Percentile 82.7%

Details

CWE
CWE-287
Status published
Products (1)
ajsquare/aj_article
Published Aug 24, 2009
Tracked Since Feb 18, 2026