CVE-2008-6236
Simple Document Management System 1.1.4-1.1.5 - SQL Injection via Login Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6236. PoCs published by Yuri.
AI-analyzed exploit summary This is a technical writeup detailing an SQL injection vulnerability in SDMS Simple Document Management System v1.1.4. The vulnerability allows authentication bypass by manipulating the SQL query in the login system due to lack of input sanitization on the password field.
Description
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This is a technical writeup detailing an SQL injection vulnerability in SDMS Simple Document Management System v1.1.4. The vulnerability allows authentication bypass by manipulating the SQL query in the login system due to lack of input sanitization on the password field.