CVE-2009-0447
MyDesign Sayac 2.0 - SQL Injection via User or Pass Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0447. PoCs published by Kacak.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in MyDesing Sayac v2.0. The exploit uses simple SQL injection payloads ('or') in both username and password fields to bypass authentication.
Description
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the user parameter (aka UserName field) or (2) the pass parameter (aka Pass field) to (a) admin/admin.asp or (b) the default URI under admin/. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in MyDesing Sayac v2.0. The exploit uses simple SQL injection payloads ('or') in both username and password fields to bypass authentication.