Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. The $eq operator matches documents where the value of a field equals the specified value.Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view