|
Date: 15 Jun 2006 11:31:59 -0000 From: [email protected] To: [email protected] Subject: HotPlugCMS_1.0 - SQL Injection Vulnerability X-Virus-Scanned: antivirus-gw at tyumen.ru HotPlugCMS doesn't check input field values, so logging in on /hotplugcms/administration/tblcontent is very easy with ' OR 1=1 /* and a SQL-inject will bypass the entire authentication process. Typical, very simple SQL Injection. peda
|
Закладки на сайте Проследить за страницей |
Created 1996-2025 by Maxim Chirkov Добавить, Поддержать, Вебмастеру |