CVE-2010-0631
eicra_car_rental-script - SQL Injection via Users and Passwords Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0631. PoCs published by Hamza 'MizoZ' N..
AI-analyzed exploit summary This exploit demonstrates an authentication bypass and SQL injection vulnerability in PHP Car Rental-Script by injecting malicious SQL queries into the login fields. The payload bypasses authentication by forcing a true condition in the SQL query.
Description
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow remote attackers to execute arbitrary SQL commands via the (1) users (username) and (2) passwords parameters.
Exploits (1)
This exploit demonstrates an authentication bypass and SQL injection vulnerability in PHP Car Rental-Script by injecting malicious SQL queries into the login fields. The payload bypasses authentication by forcing a true condition in the SQL query.