Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-0491. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in SZUserMgnt's login.php by injecting a crafted username (' or 1/*) to bypass authentication. This allows an attacker to bypass login mechanisms without valid credentials.
Description
SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.
Exploits (1)
The exploit demonstrates an SQL injection vulnerability in SZUserMgnt's login.php by injecting a crafted username (' or 1/*) to bypass authentication. This allows an attacker to bypass login mechanisms without valid credentials.