CVE-2010-1046
rostermain < 1.1 - SQL Injection via Userid or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1046. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Rostermain <= 1.1, allowing authentication bypass via crafted input in the login form. The PoC uses a trivial SQLi payload to bypass authentication by manipulating the WHERE clause.
Description
Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) userid (username) and (2) password parameters.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Rostermain <= 1.1, allowing authentication bypass via crafted input in the login form. The PoC uses a trivial SQLi payload to bypass authentication by manipulating the WHERE clause.