[] NeoSense

2DayBiz - Multiple SQL Injections

Author: Sangteamtham
type: webapps
platform: php
port: 
date_added: 2010-06-25 
date_updated: 2010-06-25 
verified: 1 
codes: OSVDB-65826;CVE-2010-2691;OSVDB-65825;OSVDB-65824 
tags: 
aliases:  
screenshot_url:  
application_url: 

$-------------------------------------------------------------------------------------------------------------------
$ 2daybiz custom T-shirt SQL Injection and Cross Site Scripting
Vulnerabilities
$ Author : Sangteamtham
$ Home : Hcegroup.net
$ Download :http://www.2daybiz.com/customt-shirt_designscript.html
$ Date :06/25/2010
$
$******************************************************************************************
$Exploit:
$
$ 1.SQL injection:
$
$ http://server/products_details.php?sbid=[id number]
$ http://server/products/products.php?pid=[id number]
$ http://server/designview.php?designid=[id number]
$
$
$
$
$******************************************************************************************
$ Greetz to: All Vietnamese hackers and Hackers out there researching for
more security
$
$
$--------------------------------------------------------------------------------------------------------------------