Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-5974. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in Active Web Mail v4. The payload 'r0' or ' 1=1--' bypasses login authentication by manipulating the SQL query.
Description
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.
Exploits (2)
This exploit demonstrates an authentication bypass via SQL injection in Active Web Mail v4. The payload 'r0' or ' 1=1--' bypasses login authentication by manipulating the SQL query.
This exploit demonstrates an authentication bypass via SQL injection in Active Price Comparison v4. The provided credentials manipulate the SQL query to bypass authentication by forcing a true condition.