CVE-2009-0853
CelerBB 0.0.2 - Authentication Bypass via Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0853. PoCs published by Salvatore Fresta.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in CelerBB 0.0.2, including SQL injection, information disclosure, and authentication bypass. It provides functional proof-of-concept code for each vulnerability, with specific payloads and attack vectors.
Description
login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the Username parameter, as demonstrated by an admin'# parameter value.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in CelerBB 0.0.2, including SQL injection, information disclosure, and authentication bypass. It provides functional proof-of-concept code for each vulnerability, with specific payloads and attack vectors.