Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13207
HistoryJun 16, 2006 - 12:00 a.m.

HotPlugCMS_1.0 - SQL Injection Vulnerability

2006-06-1600:00:00
vulners.com
8

HotPlugCMS doesn't check input field values, so logging in on /hotplugcms/administration/tblcontent
is very easy with
' OR 1=1 /*
and a SQL-inject will bypass the entire authentication process.

Typical, very simple SQL Injection.

peda