CVE-2010-0611
baal_systems < 3.8 - SQL Injection via adminlogin.php Username and Password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0611. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Baal Systems <= 3.8, allowing authentication bypass via crafted input in the admin login form. The PoC uses a classic SQLi payload to bypass authentication by manipulating the WHERE clause.
Description
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Baal Systems <= 3.8, allowing authentication bypass via crafted input in the admin login form. The PoC uses a classic SQLi payload to bypass authentication by manipulating the WHERE clause.