Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-4368. PoCs published by s4squatch.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in IBM Rational ClearQuest Web's login page, allowing authentication bypass by manipulating the username field. The provided payloads can log in as 'admin' by exploiting the vulnerable SQL query.
Description
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in IBM Rational ClearQuest Web's login page, allowing authentication bypass by manipulating the username field. The provided payloads can log in as 'admin' by exploiting the vulnerable SQL query.