SQL Injection in DCI-Taskeen
Date: 25 Feb 2006 19:45:20 -0000
From: [email protected]
To: [email protected]
Subject: SQL Injection in DCI-Taskeen
X-Virus-Scanned: antivirus-gw at tyumen.ru
Hello
Vulnerable: DCI-Taskeen v1.03
http://www.dci-designs.com
Exploit :
http://example.com/basket.php?action=addex&id=[SQL]
http://example.com/basket.php?action=[SQL]
http://example.com/basket.php?action=addr&id=[SQL]
http://example.com/cat.php?do=cat&page=1&id=[SQL]
http://example/cat.php?do=cat&page=[SQL]
Discovery by Linux_Drox
http://www.lezr.com
Best Regards