Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-1238. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in DSLogin's authentication mechanism. By injecting a malformed SQL query into the username field, an attacker can bypass authentication entirely.
Description
SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in DSLogin's authentication mechanism. By injecting a malformed SQL query into the username field, an attacker can bypass authentication entirely.