CVE-2009-3949
VivaPrograms Infinity < 2.0.5 - Unauthenticated Administrative Account Creation via Profile Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3949. PoCs published by Qabandi.
AI-analyzed exploit summary This exploit targets CVE-2009-3949 in Infinity CMS <= 2.0.5, allowing unauthenticated admin account creation via a direct HTTP POST request to /cp/profile.php. The PoC sends crafted user data to create an admin user with hardcoded credentials.
Description
cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters.
Exploits (1)
This exploit targets CVE-2009-3949 in Infinity CMS <= 2.0.5, allowing unauthenticated admin account creation via a direct HTTP POST request to /cp/profile.php. The PoC sends crafted user data to create an admin user with hardcoded credentials.