CVE-2010-0614
evalSMSI 2.1.03 - SQL Injection via ajax.php query parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0614. PoCs published by ekse.
AI-analyzed exploit summary This exploit demonstrates SQL injection and authentication bypass vulnerabilities in evalSMSI. It retrieves login and password data from the 'authentification' table via crafted UNION-based SQL queries.
Description
SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par or (3) num_quest actions.
Exploits (1)
This exploit demonstrates SQL injection and authentication bypass vulnerabilities in evalSMSI. It retrieves login and password data from the 'authentification' table via crafted UNION-based SQL queries.