CVE-2012-1673
e-ticketing - SQL Injection via Login Script Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1673. PoCs published by Mark Stanislav.
AI-analyzed exploit summary This is a writeup describing a SQL injection vulnerability in the 'e-ticketing' software's loginscript.php. The vulnerability allows for SQL injection via the 'user_name' and 'password' POST parameters, enabling authentication bypass or information disclosure.
Description
SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands via the password parameter.
Exploits (1)
This is a writeup describing a SQL injection vulnerability in the 'e-ticketing' software's loginscript.php. The vulnerability allows for SQL injection via the 'user_name' and 'password' POST parameters, enabling authentication bypass or information disclosure.