Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6525. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in HR Assist <= 1.05, allowing remote login bypass via a crafted input in the vdateUsr.asp page. The payload uses a UNION-based SQLi to bypass authentication by querying the admin table.
Description
SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in HR Assist <= 1.05, allowing remote login bypass via a crafted input in the vdateUsr.asp page. The payload uses a UNION-based SQLi to bypass authentication by querying the admin table.