Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2366. PoCs published by ThE g0bL!N.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in ForumPal v1.5. The attack leverages a classic SQLi payload in the password field to bypass login authentication.
Description
SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in ForumPal v1.5. The attack leverages a classic SQLi payload in the password field to bypass login authentication.