CVE-2005-4207

BTGrup Admin WebController Script - SQL Injection via Username and Password Fields

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-4207. PoCs published by [email protected].

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in BTGrup Admin WebController due to improper sanitization of user-supplied input in the login form. The provided credentials bypass authentication by manipulating the SQL query.

Description

SQL injection vulnerability in BTGrup Admin WebController Script allows remote attackers to execute SQL commands via the (1) Username and (2) Password fields.

Exploits (1)

exploitdb WORKING POC VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/26784

This exploit demonstrates an SQL injection vulnerability in BTGrup Admin WebController due to improper sanitization of user-supplied input in the login form. The provided credentials bypass authentication by manipulating the SQL query.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: BTGrup Admin WebController
No auth needed
Prerequisites: Access to the login page of the vulnerable application
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/249
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/419237/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21815
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15819

Scores

EPSS 0.0116
EPSS Percentile 64.1%

Details

Status published
Products (1)
btgrup/admin_webcontroller_script
Published Dec 13, 2005
Tracked Since Feb 18, 2026