Title : Redtienda E-Commerce 2.0 SQLi Vulnerability Date : 2/23/2012 Author : ITTIHACK (http://ittihack.com) Vendor : http://www.redtienda.com/english Software link : http://www.redtienda.com/english/getstarted.php Free Demo : http://manager.redtienda.net user:store - pass:beach65 Version : 2.0 Tested on : Windows 7 About : Redtienda is an online program that you use to create and manage your own online store. There are both free and commercial software. Vulnerable File : pro.php Exploit : http://site/path/pro.php?id=[SQLi] Vulnerable websites : http://store.redtienda.net/pro.php?id=6 http://www.directfans.com/pro.php?id=138115 http://www.importdirecto.com/pro.php?id=246674 Solution : I contacted the developers, hope to be fixed as soon as possible Special Greating to: alex m7md