CVE-2006-0372
Insane Visions BlogPHP - SQL Injection via Cookie Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0372. PoCs published by imei.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in BlogPHP 1.2 by bypassing authentication via a crafted password field. The payload 'imei' or '1'='1' manipulates the SQL query to always return true, allowing unauthorized access.
Description
Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in BlogPHP 1.2 by bypassing authentication via a crafted password field. The payload 'imei' or '1'='1' manipulates the SQL query to always return true, allowing unauthorized access.