Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6543. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SpotLight CRM 1.0's login.asp page, allowing an attacker to modify user credentials via crafted POST requests. The PoC provides example payloads to update passwords and usernames.
Description
Multiple SQL injection vulnerabilities in login.asp in AppIntellect SpotLight CRM 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) login (UserName) and possibly (2) password parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in SpotLight CRM 1.0's login.asp page, allowing an attacker to modify user credentials via crafted POST requests. The PoC provides example payloads to update passwords and usernames.