Redtienda E-Commerce 2.0 SQL Injection

2012.02.25
Credit: ITTIHACK
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

Title : Redtienda E-Commerce 2.0 SQLi Vulnerability Date : 2/23/2012 Author : ITTIHACK (http://ittihack.com) Vendor : http://www.redtienda.com/english Software link : http://www.redtienda.com/english/getstarted.php Free Demo : http://manager.redtienda.net user:store - pass:beach65 Version : 2.0 Tested on : Windows 7 About : Redtienda is an online program that you use to create and manage your own online store. There are both free and commercial software. Vulnerable File : pro.php Exploit : http://site/path/pro.php?id=[SQLi] Vulnerable websites : http://store.redtienda.net/pro.php?id=6 http://www.directfans.com/pro.php?id=138115 http://www.importdirecto.com/pro.php?id=246674 Solution : I contacted the developers, hope to be fixed as soon as possible Special Greating to: alex m7md

References:

http://www.redtienda.com/english


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top