CVE-2012-6626
Brian Cabunac Browser TO Email Phone Message System - SQL Injection
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2012-6626. PoCs published by Jean Pascal Pereira.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in b2ePMS 1.0, allowing authentication bypass via crafted input in the login form. The PoC provides a working payload to bypass authentication by manipulating the SQL query.
Description
SQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username field.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in b2ePMS 1.0, allowing authentication bypass via crafted input in the login form. The PoC provides a working payload to bypass authentication by manipulating the SQL query.