CVE-2015-4658
Milw0rm Clone Script 1.0 - SQL Injection via usr or pwd Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-4658. PoCs published by walid naceri.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Milw0rm Clone Script v1.0, allowing authentication bypass via crafted input in the login form. The PoC provides two payloads to bypass authentication by manipulating the SQL query.
Description
Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) usr or (2) pwd parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Milw0rm Clone Script v1.0, allowing authentication bypass via crafted input in the login form. The PoC provides two payloads to bypass authentication by manipulating the SQL query.