Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6142. PoCs published by S.W.A.T..
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Flexphpic and Flexphpic Pro, allowing authentication bypass via a crafted username and password input. The exploit leverages a simple SQL injection payload to bypass the login mechanism.
Description
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.x versions, allow remote attackers to execute arbitrary SQL commands via (1) the checkuser parameter (aka username field), or (2) the checkpass parameter (aka password field), to admin/index.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Flexphpic and Flexphpic Pro, allowing authentication bypass via a crafted username and password input. The exploit leverages a simple SQL injection payload to bypass the login mechanism.