CVE-2023-53960
CRITICALSOUND4 IMPACT/FIRST/PULSE/Eco 2.x - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53960. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x, allowing authentication bypass via the 'password' POST parameter in 'index.php'. The provided payload manipulates the SQL query to bypass authentication.
Description
SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized access to the system.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x, allowing authentication bypass via the 'password' POST parameter in 'index.php'. The provided payload manipulates the SQL query to bypass authentication.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H