Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0462. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in ClickCart 6.0. It provides credentials to bypass login by injecting a tautology into the SQL query.
Description
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field) or (2) the txtPassword parameter (aka password field) to customer_login.asp. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in ClickCart 6.0. It provides credentials to bypass login by injecting a tautology into the SQL query.