CVE-2009-2604
Zen Help Desk 2.1 - SQL Injection via Userid or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2604. PoCs published by TiGeR-Dz.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass and SQL injection vulnerability in Zen Help Desk Version 2.1. It provides specific payloads to bypass authentication by injecting SQL into the username field.
Description
Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp.
Exploits (1)
This exploit demonstrates an authentication bypass and SQL injection vulnerability in Zen Help Desk Version 2.1. It provides specific payloads to bypass authentication by injecting SQL into the username field.