Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-20126. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in KB Affiliate Referral PHP Script V1.0 by injecting SQL code into the login form. The attack uses a simple SQL injection payload to bypass authentication.
Description
A vulnerability was found in KB Affiliate Referral Script 1.0. It has been classified as critical. This affects an unknown part of the file /index.php. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in KB Affiliate Referral PHP Script V1.0 by injecting SQL code into the login form. The attack uses a simple SQL injection payload to bypass authentication.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L