Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6163. PoCs published by Aria-Security Team.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in DWD Realty by bypassing authentication via a crafted password field. The payload 'anything' OR 'x'='x' manipulates the SQL query to authenticate as the 'Admin' user without valid credentials.
Description
SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the pword (aka Password) parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in DWD Realty by bypassing authentication via a crafted password field. The payload 'anything' OR 'x'='x' manipulates the SQL query to authenticate as the 'Admin' user without valid credentials.