CVE-2008-6950
Bankoi WebHosting Control Panel 1.20 - SQL Injection via Login Username or Password Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6950. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Bankoi Webhost Panel 1.20. By injecting SQL code into the username and password fields, an attacker can bypass authentication and gain unauthorized access.
Description
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
Exploits (1)
This exploit demonstrates an SQL injection authentication bypass in Bankoi Webhost Panel 1.20. By injecting SQL code into the username and password fields, an attacker can bypass authentication and gain unauthorized access.