==> ABOUT ME: --- TAURUS OMAR --- INDEPENDENT SECURITY RESEARCHER --- ACCESOILEGAL.BLOGSPOT.COM --- @omartaurus --- omar-taurus[at]dragonsecurity[dot]org --- omar-taurus[at]live[dot]com ===> INFO: Author : TAURUS OMAR Category : Webapps / 0day Title Exploit : Hosting Syste-Mar - SQL Injection Vulnerability Vendor : Hosting Syste-Mar URL Vendor : http://www.syste-mart.com/ Google Dork : intext:"Hosting Syste-Mart" ==> SAMPLE'S SQLi: http://www.entremodelos.com.mx/verModelo.php?id=28 [SQL Injection] http://www.piccola.com.mx/verLinea.php?id=3 [SQL Injection] http://www.puntoforza.com/verLinea.php?id=19 [SQL Injection] http://www.puntoforza.com/verLinea.php?id=19 [SQL Injection] http://laglorietachapalita.com/verObra.php?idObra=388&id=82 [SQL Injection] MORE IN GOOGLE..