Exploitation Summary
EIP tracks 2 public exploits for CVE-2005-1943. PoCs published by hack_912.
AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in Loki Download Manager via the 'default.asp' script. The PoC provides credentials with a malformed password to bypass authentication.
Description
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.
Exploits (2)
The exploit demonstrates an SQL injection vulnerability in Loki Download Manager via the 'default.asp' script. The PoC provides credentials with a malformed password to bypass authentication.
This exploit demonstrates an SQL injection vulnerability in Loki Download Manager's 'catinfo.asp' script. The PoC uses a UNION-based SQLi to extract admin credentials from the 'tblAdm' table.