[] NeoSense

PayPal Shop Digital - SQL Injection

Author: DeadLy DeMon
type: webapps
platform: php
port: 
date_added: 2010-12-18 
date_updated: 2010-12-18 
verified: 1 
codes: OSVDB-69945;CVE-2010-4846 
tags: 
aliases:  
screenshot_url:  
application_url: 

+Name : PayPal Shop Digital <<= SQL injection Vulnerability

+Autor : DeadLy DeMon

+Date : 18.12.2010

+Script : PayPal Shop Digital

+Vendor : http://www.mhproducts.de/php-scripte-5/pal-pal-shop-digital.html

+Price : 15,99 Euro

+Language : PHP

+Tests : Windows XP SP 3 and Backtrack4 any other OS

+Discovered by DeadLy DeMon

+ Cyber - Warrior TIM =>> *www.cyber-warrior.org*

+Greetz to All System-Hacker, BlackApple , F0RTYS3V3N and All KinqSqlZCrew
Members

---------------------------------------------------------------------------------------



Var mı içinizde beni tanıyan?
Yaşanmadan çözülemeyen sır benim.
Kalmasada şöhretimi duymayan,
Kimliğimi tarif etmek zor benim..

                        KinqSqlZ Crew Akar...

----------------------------------------------------------------------------------------


Bug ;

target/path/view_item.php?ItemID=[Sql Inj.]


---------------------------------------------------------------------------------------