CVE-2005-0368
CMScore - SQL Injection via EntryID, searchterm, or username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-0368. PoCs published by GHC.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in CMS Core by injecting a malicious username to bypass authentication. The payload 'Administrator'/*' is used to log in as an administrator without valid credentials.
Description
Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in CMS Core by injecting a malicious username to bypass authentication. The payload 'Administrator'/*' is used to log in as an administrator without valid credentials.