CVE-2012-1026
XRay CMS 1.1.1 - SQL Injection via Username or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1026. PoCs published by chap0.
AI-analyzed exploit summary This is a writeup describing an SQL injection vulnerability in XRayCMS 1.1.1, specifically an authentication bypass via the username field. The exploit involves injecting ' or 1=1# to log in as admin, with no actual exploit code provided.
Description
Multiple SQL injection vulnerabilities in login2.php in XRay CMS 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
Exploits (1)
This is a writeup describing an SQL injection vulnerability in XRayCMS 1.1.1, specifically an authentication bypass via the username field. The exploit involves injecting ' or 1=1# to log in as admin, with no actual exploit code provided.