CVE-2009-1503
TigerDMS - SQL Injection via Login Username and Password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1503. PoCs published by ThE g0bL!N.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Tiger DMS's login.php, allowing authentication bypass via crafted input. The PoC uses a classic SQLi payload to bypass authentication by manipulating the WHERE clause.
Description
Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Tiger DMS's login.php, allowing authentication bypass via crafted input. The PoC uses a classic SQLi payload to bypass authentication by manipulating the WHERE clause.