CVE-2011-0748

phplist < 2.10.13 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-0748. PoCs published by Cyber-Crystal.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in phplist 2.10.9 that allows an attacker to add an admin account and an XSS vulnerability that can be triggered via a crafted POST request. The PoC includes HTML forms to exploit these vulnerabilities.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) edit administrator accounts.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Cyber-Crystal · htmlwebappsphp
https://www.exploit-db.com/exploits/18419

This exploit demonstrates a CSRF vulnerability in phplist 2.10.9 that allows an attacker to add an admin account and an XSS vulnerability that can be triggered via a crafted POST request. The PoC includes HTML forms to exploit these vulnerabilities.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: phplist version 2.10.9
No auth needed
Prerequisites: Access to the target phplist admin interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/517400/100/0/threaded
Various Sources x_refsource_misc
http://int21.de/cve/CVE-2011-0748-phplist.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44041
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/78549
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18419
Various Sources x_refsource_confirm
http://www.phplist.com/?lid=516
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72746
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8199
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51681

Scores

EPSS 0.0147
EPSS Percentile 70.3%

Details

CWE
CWE-352
Status published
Products (50)
tincan/phplist 1.0
tincan/phplist 1.0.1
tincan/phplist 1.1.2b
tincan/phplist 1.1.3b
tincan/phplist 1.1.4b
tincan/phplist 1.1.5
tincan/phplist 1.1.5b
tincan/phplist 1.1.6
tincan/phplist 1.1.7
tincan/phplist 1.3.5
... and 40 more
Published Apr 13, 2011
Tracked Since Feb 18, 2026