There is a vulnerability in CMSimple 3.3 that allows to deface website using CMSimple.
http://www.htbridge.ch/advisory/xss_vul ... imple.html
In short, passing "> to site_title field of the form disrupts adm.php in a way that other settings, including password, can be changed.
My website was defaced using apparently this method.
I tried various solutions, but currently settled on disabling admin side completely.
Does anyone had similar problem or have any idea how to deal with this and keep the admin side?

