36 lines
No EOL
1.5 KiB
Text
36 lines
No EOL
1.5 KiB
Text
Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
|
|
Exploit Title:Hotel / Resort Site Script with OnLine Reservation System
|
|
SQLi Vulnerable
|
|
Published: 2010-06-08
|
|
Vendor url:http://www.mformula.com.br
|
|
Greetz to:Sid3^effects, aa_Numb, M4n0j and to all ICW members
|
|
|
|
#############################################################################################################################################################################
|
|
|
|
DESCRIPTION:
|
|
|
|
Internal system for total administration of the site.
|
|
Available site in the languages Portuguese, Spanish, Japanese, English,
|
|
Italian, French & German.
|
|
System and reservation advanced search onnline/offline, Control of orders
|
|
and reservations, RSS/XML feed, Optimization in search engines, SiteMap
|
|
Google,
|
|
Yahoo and Bing, Support Inns, Hotel and Resorts, Unlimited Gallery of
|
|
Photos, Supported to any type of personalized option (Color, Size, Type,
|
|
etc), Tool of relationship between services, Tool of newsletters for
|
|
customers,
|
|
Personalization of the layout, colors and texts of the site in agreement
|
|
your mark, Reports detailed on the site
|
|
###############################################################################################################################################################################
|
|
|
|
Vulnerability:
|
|
|
|
contains SQLi Vulenrable.
|
|
|
|
demo:-
|
|
http://server/extrapage.php?cat_id=-1'[SQLi]
|
|
|
|
################################################################################################################################################################################
|
|
--
|
|
With R3gards,
|
|
L0rd CrusAd3r |