CVE-2008-5633
ActiveVotes 2.2 - SQL Injection via Username and Password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5633. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in ActiveVotes v2.2. It provides credentials to bypass login by injecting a tautology into the SQL query.
Description
SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in ActiveVotes v2.2. It provides credentials to bypass login by injecting a tautology into the SQL query.