CVE-2008-5959
Active Test 2.1 - SQL Injection via Useremail or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5959. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in Active Test v2.1. The provided credentials exploit a SQL injection vulnerability to bypass authentication.
Description
Multiple SQL injection vulnerabilities in start.asp in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or (2) password parameter (aka password field). NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in Active Test v2.1. The provided credentials exploit a SQL injection vulnerability to bypass authentication.