# Exploit Title: JOT Online Store (E-Commerce System) SQL Injection # Date: 2011 # Author: Eyup CELIK # Software Link: http://www.justonlinetoday.com # Version: All Version # Tested on: All versions are Vulnerability ISSUE SQL Injection can be done using the command input Vulnerable Page: index.php Example: index.php/ Exploit: index.php/1' Demo: http://www.justonlinetoday.com/demo_online_store/themes/2/index.php/1%27 Thanks, Eyup CELIK Bilgi Teknolojileri Güvenlik Uzmani http://www.eyupcelik.com.tr