CVE-2008-6220
Simple Document Management System 1.1.4-1.1.5 - SQL Injection via Login Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6220. PoCs published by Yuri.
AI-analyzed exploit summary This is a technical writeup detailing an SQL injection vulnerability in SDMS Simple Document Management System v1.1.4. The vulnerability allows authentication bypass by manipulating the SQL query in the login system due to lack of input sanitization on the password field.
Description
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the pass parameter.
Exploits (1)
This is a technical writeup detailing an SQL injection vulnerability in SDMS Simple Document Management System v1.1.4. The vulnerability allows authentication bypass by manipulating the SQL query in the login system due to lack of input sanitization on the password field.