Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
HotPlugCMS_1.0 - SQL Injection Vulnerability Jun 15 2006 11:31AM
guest01 gmail com
HotPlugCMS doesn't check input field values, so logging in on /hotplugcms/administration/tblcontent

is very easy with

' OR 1=1 /*

and a SQL-inject will bypass the entire authentication process.

Typical, very simple SQL Injection.

peda

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus