D1rt3 Dud3

1 exploit Active since Dec 2011
CVE-2011-5031 EXPLOITDB text WORKING POC
capexweb 1.1 - SQL Injection via dfuserid and dfpassword Parameters
Multiple SQL injection vulnerabilities in servlet/capexweb.parentvalidatepassword in cApexWEB 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) dfuserid and (2) dfpassword parameters. NOTE: some of these details are obtained from third party information.