CVE-2006-0135
TheWebForum < 1.2.1 - SQL Injection via Login Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0135. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in TheWebForum, including examples for authentication bypass and password hash retrieval. It outlines the lack of input sanitization but does not include executable exploit code.
Description
SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).
Exploits (1)
The provided text describes SQL injection vulnerabilities in TheWebForum, including examples for authentication bypass and password hash retrieval. It outlines the lack of input sanitization but does not include executable exploit code.