Description
VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials. Attackers can exploit the login page by injecting 'admin' or 1=1-- - payload to gain unauthorized access to the administrative interface.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
[Edd13Mora]
References
www.exploit-db.com/exploits/51033 (ExploitDB-51033)
www.viaviweb.com (Vendor Homepage)
www.vulncheck.com/...aper-admin-sql-injection-via-login-page (VulnCheck Advisory: VIAVIWEB Wallpaper Admin 1.0 - SQL Injection via Login Page)