CVE-2018-25424
HIGHGate Pass Management System 2.1 SQL Injection via login-exec.php
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25424. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Gate Pass Management System 2.1 via the login-exec.php endpoint. The payload uses URL-encoded SQL syntax to bypass authentication by injecting a tautology (OR 1=1) into the login and password parameters.
Description
Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form parameters to authenticate without valid credentials and gain access to the application.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Gate Pass Management System 2.1 via the login-exec.php endpoint. The payload uses URL-encoded SQL syntax to bypass authentication by injecting a tautology (OR 1=1) into the login and password parameters.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N