CVE-2009-1852
Graphiks MyForum 1.3 - SQL Injection via Username or Password Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1852. PoCs published by ThE g0bL!N.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in MyForum 1.3. It leverages improper input validation in the login mechanism to bypass authentication by injecting a tautology (' or '1=1) into the username or password field.
Description
Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in MyForum 1.3. It leverages improper input validation in the login mechanism to bypass authentication by injecting a tautology (' or '1=1) into the username or password field.