Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0451. PoCs published by Dimi4.
AI-analyzed exploit summary This exploit demonstrates an SQL injection and authentication bypass vulnerability in SkaLinks 1.5. The flaw lies in the `IsAdmin` function, which directly interpolates user-controlled cookie values into an SQL query without sanitization.
Description
SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Admin name field to the default URI under admin/.
Exploits (1)
This exploit demonstrates an SQL injection and authentication bypass vulnerability in SkaLinks 1.5. The flaw lies in the `IsAdmin` function, which directly interpolates user-controlled cookie values into an SQL query without sanitization.