CVE-2019-25335
HIGH7070 Hazr Profesyonel Web Sitesi 1.0 - Authentication Bypass via SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25335. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in PRO-7070 Hazır Profesyonel Web Sitesi 1.0 by injecting SQL-like syntax into the login form. The PoC provides credentials that bypass authentication by leveraging a logical flaw in the login mechanism.
Description
PRO-7070 Hazır Profesyonel Web Sitesi version 1.0 contains an authentication bypass vulnerability in the administration panel login page. Attackers can bypass authentication by using '=' 'or' as both username and password to gain unauthorized access to the administrative interface.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in PRO-7070 Hazır Profesyonel Web Sitesi 1.0 by injecting SQL-like syntax into the login form. The PoC provides credentials that bypass authentication by leveraging a logical flaw in the login mechanism.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N