Full Site for Restaurant suffers from a remote SQL injection vulnerability.
8fd5cb41fa8f1440fae427094cd4d7b0c970f247c526776d2c8942dd8e7bd857
Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
Exploit Title: Full Site for Restaurant SQL Injection Vulnerability
Vendor url:https://www.mformula.com.br/
Version:n/a
Price:100$
Published: 2010-06-11
Greetz to:Sid3^effects, MaYur, M4n0j, Dark Blue, S1ayer,d3c0d3r,KD and to all ICW & AH members.
Spl Greetz to:inj3ct0r.com Team
#####################################################################################################################################################################################################
Description:
* Full Site for Restaurant SQL Injection Vulnerability *
Internal system for total administration of the site, Available site in the languages Portuguese, EspaƱol, English, Japanese, French, Italian and German, Unlimited Extra Pages and Sub Pages, Menu OnLine, Unlimited Gallery of Photos Code: PHP 5.0
#######################################################################################################################################################################################################
Vulnerability:
*SQLi Vulnerability
DEMO URL :
https://restaurant.mformula.com.br/?lang=[sqli]
https://restaurant.mformula.com.br/extrapage.php?cat_id=[sqli]
# 0day n0 m0re #