Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-0417. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in miniBloggie's login mechanism. By injecting SQL code into the username and password fields, an attacker can bypass authentication.
Description
SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in miniBloggie's login mechanism. By injecting SQL code into the username and password fields, an attacker can bypass authentication.