CVE-2008-6329
Pre ASP Job Board - SQL Injection via Username or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6329. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in PRE JOB BOARD, allowing authentication bypass via crafted input in the login form. The payload manipulates the SQL query to return true, granting unauthorized access.
Description
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password parameters, as reachable from Employee/emp_login.asp. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in PRE JOB BOARD, allowing authentication bypass via crafted input in the login form. The payload manipulates the SQL query to return true, granting unauthorized access.