CVE-2008-6390
Membership Manager Pro - SQL Injection via Login Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6390. PoCs published by Cyber-Zone.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Ocean12 Membership Manager Pro via SQL injection. The PoC provides a simple payload to bypass login by injecting a tautology into the username field.
Description
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Ocean12 Membership Manager Pro via SQL injection. The PoC provides a simple payload to bypass login by injecting a tautology into the username field.