CVE-2008-1726
KnowledgeQuest 2.6 - SQL Injection via kqid or username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1726. PoCs published by Virangar Security.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in KnowledgeQuest 2.6, allowing unauthorized data extraction and authentication bypass via crafted HTTP requests. The PoC includes specific URLs and payloads to exploit the vulnerabilities.
Description
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username parameter to (c) logincheck.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in KnowledgeQuest 2.6, allowing unauthorized data extraction and authentication bypass via crafted HTTP requests. The PoC includes specific URLs and payloads to exploit the vulnerabilities.