CVE-2008-6907
2532gigs 1.2.2 - SQL Injection via Username and Password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6907. PoCs published by StAkeR.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Gigs 1.2.2 Stable, allowing remote login bypass via crafted input in the username and password fields. The PoC uses a classic SQLi payload to bypass authentication.
Description
Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, as accessible from a form generated by index.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Gigs 1.2.2 Stable, allowing remote login bypass via crafted input in the username and password fields. The PoC uses a classic SQLi payload to bypass authentication.