CVE-2014-10020
Simple e-document 1.31 - SQL Injection via Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-10020. PoCs published by vinicius777.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Simple e-document v1.31, allowing an attacker to bypass authentication by injecting a crafted username. The PoC includes a Burp request and highlights the vulnerable code in login.php.
Description
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Simple e-document v1.31, allowing an attacker to bypass authentication by injecting a crafted username. The PoC includes a Burp request and highlights the vulnerable code in login.php.