Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-3608. PoCs published by KnocKout.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in wpQuiz 2.7 via SQL injection. By using the credentials ' or '1=1 for both username and password, an attacker can bypass authentication and gain unauthorized access to the admin or user panels.
Description
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) password (pw) parameters to (a) admin.php or (b) user.php.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in wpQuiz 2.7 via SQL injection. By using the credentials ' or '1=1 for both username and password, an attacker can bypass authentication and gain unauthorized access to the admin or user panels.