CVE-2013-2690
Synchroweb SynConnect 2.0 - SQL Injection via LoginID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-2690. PoCs published by Bhadresh Patel.
AI-analyzed exploit summary This is a detailed vulnerability writeup for CVE-2013-2690, describing an error-based SQL injection in SynConnect's index.php. The vulnerability allows remote attackers to extract database information, including admin credentials, via the 'loginid' parameter.
Description
SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff action.
Exploits (1)
This is a detailed vulnerability writeup for CVE-2013-2690, describing an error-based SQL injection in SynConnect's index.php. The vulnerability allows remote attackers to extract database information, including admin credentials, via the 'loginid' parameter.