CVE-2008-6950

Bankoi WebHosting Control Panel 1.20 - SQL Injection via Login Username or Password Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6950. PoCs published by R3d-D3V!L.

AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Bankoi Webhost Panel 1.20. By injecting SQL code into the username and password fields, an attacker can bypass authentication and gain unauthorized access.

Description

Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.

Exploits (1)

exploitdb WORKING POC VERIFIED
by R3d-D3V!L · textwebappsasp
https://www.exploit-db.com/exploits/7120

This exploit demonstrates an SQL injection authentication bypass in Bankoi Webhost Panel 1.20. By injecting SQL code into the username and password fields, an attacker can bypass authentication and gain unauthorized access.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Bankoi Webhost Panel 1.20
No auth needed
Prerequisites: Access to the login page of the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46637
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32299
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7120

Scores

EPSS 0.0097
EPSS Percentile 57.1%

Details

CWE
CWE-89
Status published
Products (1)
webhost-panel/bankoi_webhosting_control_panel 1.20
Published Aug 12, 2009
Tracked Since Feb 18, 2026