CVE-2010-2338
VU Web Visitor Analyst - SQL Injection via redir.asp Username or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2338. PoCs published by L0rd CrusAd3r.
AI-analyzed exploit summary This is a writeup describing an authentication bypass vulnerability in VU Web Visitor Analyst due to SQL injection in the admin login page. The exploit involves using the string 'a' or '1'='1' for both username and password fields.
Description
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
This is a writeup describing an authentication bypass vulnerability in VU Web Visitor Analyst due to SQL injection in the admin login page. The exploit involves using the string 'a' or '1'='1' for both username and password fields.