Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-0841. PoCs published by kre0n.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in the login mechanism, allowing authentication bypass by manipulating the SQL query to always evaluate to true and set the admin flag.
Description
SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote attackers to execute arbitrary SQL commands, as demonstrated via (1) the person parameter to people.php or (2) the Login field.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in the login mechanism, allowing authentication bypass by manipulating the SQL query to always evaluate to true and set the admin flag.