Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6671. PoCs published by Aria-Security Team.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in InstantSoftwares Dating Site by bypassing authentication via a crafted password field. The payload 'anything' OR 'x'='x' manipulates the SQL query to authenticate as any user, including 'Admin'.
Description
SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Password parameter, a different product than CVE-2006-6021. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in InstantSoftwares Dating Site by bypassing authentication via a crafted password field. The payload 'anything' OR 'x'='x' manipulates the SQL query to authenticate as any user, including 'Admin'.