[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : PayPal Shop Digital SQL Injection Vulnerability
# Published : 2010-12-18
# Author : DeadLy DeMon
# Previous Title : Vacation Rental Script v4.0 Arbitrary File Upload Vulnerability
# Next Title : Joomla Component Jotloader 2.2.1 Local File Inclusion Vulnerability


+Name : PayPal Shop Digital <<= SQL injection Vulnerability

+Autor : DeadLy DeMon

+Date : 18.12.2010

+Script : PayPal Shop Digital

+Vendor : http://www.mhproducts.de/php-scripte-5/pal-pal-shop-digital.html

+Price : 15,99 Euro

+Language : PHP

+Tests : Windows XP SP 3 and Backtrack4 any other OS

+Discovered by DeadLy DeMon

+ Cyber - Warrior TIM =>> *www.cyber-warrior.org*

+Greetz to All System-Hacker, BlackApple , F0RTYS3V3N and All KinqSqlZCrew
Members

---------------------------------------------------------------------------------------



Var m? i?inizde beni tan?yan?
Ya?anmadan ??z¨¹lemeyen s?r benim.
Kalmasada ??hretimi duymayan,
Kimli?imi tarif etmek zor benim..

                        KinqSqlZ Crew Akar...

----------------------------------------------------------------------------------------


Bug ;

target/path/view_item.php?ItemID=[Sql Inj.]


---------------------------------------------------------------------------------------