CVE-2009-4826
ScriptsEz Mini Hosting Panel - Cross-Site Request Forgery via Admin Panel Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4826. PoCs published by Milos Zivanovic.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Request Forgery (XSRF) vulnerability in mini Hosting Panel, allowing an attacker to change admin settings such as ID, password, and email by tricking an authenticated admin into submitting a malicious form.
Description
Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action.
Exploits (1)
This exploit demonstrates a Cross-Site Request Forgery (XSRF) vulnerability in mini Hosting Panel, allowing an attacker to change admin settings such as ID, password, and email by tricking an authenticated admin into submitting a malicious form.