CVE-2010-4186

OnlineTechTools OWOS Professional Edition 2.10 - SQL Injection via Password Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2010-4186. PoCs published by VSN, L0rd CrusAd3r.

AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in Online Work Order Suite 2.10, with an example payload (' or 1=1 or ''='') but lacks executable exploit code. It references a security advisory without a functional PoC.

Description

SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: some of these details are obtained from third party information.

Exploits (2)

exploitdb WRITEUP VERIFIED
by VSN · textwebappsphp
https://www.exploit-db.com/exploits/34951

The provided text describes an SQL injection vulnerability in Online Work Order Suite 2.10, with an example payload (' or 1=1 or ''='') but lacks executable exploit code. It references a security advisory without a functional PoC.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Online Work Order Suite 2.10
No auth needed
Prerequisites: Network access to the vulnerable application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by L0rd CrusAd3r · textwebappsasp
https://www.exploit-db.com/exploits/15397

This is a writeup describing an authentication bypass vulnerability in Onlinetechtools OWOS: Professional Edition. The vulnerability can be exploited using the SQL injection pattern ' or 1=1 or ''='' to bypass authentication.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Onlinetechtools OWOS: Professional Edition 2.10
No auth needed
Prerequisites: Access to the login interface of the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42111
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44608
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/62972
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/68972
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15397

Scores

EPSS 0.0103
EPSS Percentile 59.2%

Details

CWE
CWE-89
Status published
Products (1)
onlinetechtools.com/oasys_professional 2.10
Published Nov 05, 2010
Tracked Since Feb 18, 2026