ellistonSPORT Remote SQL Injection Vulnerability
Software : ellistonSPORT
Date : 4/1/2012
Vendor : http://ellistonsport.com/
Get App. : http://ellistonsport.com/pricing.php
Price : $59.99
Dork : inurl:"/showPlayer.php?id=" intext:"powered by ellistonSPORT"
Author : ITTIHACK
Home : http://ittihack.com
Vulnerable file : showPlayer.php | showPage.php | showNews.php
Exploit : http://site/[path]/showPlayer.php?id=[SQLi]
http://site/[path]/showPage.php?id=[SQLi]
http://site/[path]/showNews.php?id=[SQLi]