CVE-2009-1026
Kim Websites 1.0 - SQL Injection via Username or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1026. PoCs published by Virangar Security.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Kim Websites 1.0, allowing authentication bypass by injecting a malicious payload into the username field. The vulnerability arises from improper sanitization of user input in the login.php file.
Description
Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Kim Websites 1.0, allowing authentication bypass by injecting a malicious payload into the username field. The vulnerability arises from improper sanitization of user input in the login.php file.