CVE-2009-4674

Mole Group Sky Hunter - RCE

Title source: llm

Description

admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to change an arbitrary password via a modified user_id field.

Exploits (1)

exploitdb WORKING POC VERIFIED
by G4N0K · htmlwebappsphp
https://www.exploit-db.com/exploits/8774

Scores

EPSS 0.0265
EPSS Percentile 85.8%

Details

CWE
CWE-255
Status published
Products (2)
mole-group/bus_ticket_script
mole-group/sky_hunter_airline_ticket_sale_script
Published Mar 05, 2010
Tracked Since Feb 18, 2026