CVE-2005-2012
paFAQ 1.0 Beta 4 - SQL Injection via Username or ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2012. PoCs published by GulfTech Security.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in paFaq's admin login page. The crafted URL injects a UNION-based SQL query to bypass authentication by retrieving admin credentials from the database.
Description
Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in paFaq's admin login page. The crafted URL injects a UNION-based SQL query to bypass authentication by retrieving admin credentials from the database.