1 ########################################## 1 0 I'm L0rd CrusAd3r member from Inj3ct0r Team 1 1 ########################################## 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=1 Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com] Exploit Title:Shareasale Script SQL Vulnerable Vendor url:http://www.jce-tech.com Version:1 Price:n/a Published: 2010-06-21 Greetz to:r0073r (inj3ct0r.com), Sid3^effects, MaYur, MA1201, Sonic Bluehat. Special Greetz: Topsecure.net, inj3ct0r Team Shoutzz:- To all ICW members ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~ Description: Shareasale Script is a PHP and MYSQL based script that can be used to import and display product data feeds from Shareasale.com. The script comes complete with a default template, a complete backend administration functionality, and much more. Code: PHP 4.0 ~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~ Vulnerability: *SQLi Vulnerability DEMO URL : http://server/merchant_product_list.php?merchant_id=[sqli] # 0day n0 m0re # # L0rd CrusAd3r #