CVE-2008-6627
WEBDOMAIN WebShop <= 1.2 - SQL Injection via getin.php Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6627. PoCs published by Hakxer.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in WebBDOMAIN Webshop by injecting a SQL tautology into the username field. The payload bypasses authentication by leveraging improper input validation.
Description
SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in WebBDOMAIN Webshop by injecting a SQL tautology into the username field. The payload bypasses authentication by leveraging improper input validation.