CVE-2004-2067
Jaws Framework and Content Management System 0.4 - SQL Injection via User, Password, or Crypted_Password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2067. PoCs published by Fernando Quintero.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in JAWS controlpanel.php by manipulating the password field to inject a malicious SQL query. The JavaScript function bypasses authentication by setting the password to a tautology.
Description
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in JAWS controlpanel.php by manipulating the password field to inject a malicious SQL query. The JavaScript function bypasses authentication by setting the password to a tautology.