Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-5635. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in Active Membership v2. The provided credentials manipulate the SQL query to always return true, allowing unauthorized access.
Description
SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in Active Membership v2. The provided credentials manipulate the SQL query to always return true, allowing unauthorized access.