CVE-2006-5217
Emek Portal 2.1 - SQL Injection via Kullanici Adi and Sifre Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5217. PoCs published by Dj ReMix.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Emek Portal 2.1 by providing a crafted HTML form that submits malicious input to bypass authentication. The payload uses single quotes and logical OR operators to manipulate the SQL query.
Description
SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp, also known as the Kullanici Adi (k_a) and Sifre (sifre) parameters.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Emek Portal 2.1 by providing a crafted HTML form that submits malicious input to bypass authentication. The payload uses single quotes and logical OR operators to manipulate the SQL query.