Exploitation Summary
EIP tracks 2 public exploits for CVE-2006-2887. PoCs published by FarhadKey.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in myNewsletter <= 1.1.2, allowing an attacker to bypass authentication by manipulating the login form's action and injecting a malicious SQL query.
Description
Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp.
Exploits (2)
This exploit demonstrates an SQL injection vulnerability in myNewsletter <= 1.1.2, allowing an attacker to bypass authentication by manipulating the login form's action and injecting a malicious SQL query.
This is a functional SQL injection PoC for CVE-2006-2887, targeting myNewsletter 1.1.2. It bypasses authentication by injecting a malicious SQL query into the login form, allowing unauthorized access.