Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6326.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in Simple Customer 1.2. By submitting a crafted password (' or ' 1=1), the login mechanism is bypassed due to improper input sanitization.
Description
SQL injection vulnerability in login.php in Simple Customer as downloaded on 20081118 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in Simple Customer 1.2. By submitting a crafted password (' or ' 1=1), the login mechanism is bypassed due to improper input sanitization.