CVE-2008-6286
Active Newsletter 4.3 - SQL Injection via Email or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6286. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in Active Newsletter v4.3. The provided credentials leverage a classic SQLi technique to bypass login validation.
Description
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in Active Newsletter v4.3. The provided credentials leverage a classic SQLi technique to bypass login validation.