Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2168. PoCs published by Qabandi.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in EgyPlus 7ml <= 1.0.1, allowing authentication bypass via manipulated cookie or POST data. The vulnerability arises from unsanitized user input in the login process.
Description
cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and password parameters.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in EgyPlus 7ml <= 1.0.1, allowing authentication bypass via manipulated cookie or POST data. The vulnerability arises from unsanitized user input in the login process.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H