CVE-2021-3278
CRITICALLocal Service Search Engine Management System 1.0 - Auth Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-3278. PoCs published by Aditya Wakhlu.
AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Local Service Search Engine Management System 1.0. The payload 'Aditya' or 1=1# bypasses login by manipulating the SQL query to always return true.
Description
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.
Exploits (1)
This exploit demonstrates an SQL injection authentication bypass in Local Service Search Engine Management System 1.0. The payload 'Aditya' or 1=1# bypasses login by manipulating the SQL query to always return true.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H