|
HotPlugCMS doesn't check input field values, so logging in on /hotplugcms/administration/tblcontent=0D
is very easy with=0D
' OR 1=1 /*=0D
and a SQL-inject will bypass the entire authentication process.=0D
=0D
Typical, very simple SQL Injection.=0D
=0D
peda