# Exploit Title: Andabate.com SQL Injection Vulnerability
# Author: magret
# Vendor or Software Link: Andabate.com
# Email: magret.canard@free.fr
# MSN: magret-2-canard@hotmail.fr
# ICQ: 585652602
# Category: webapps
# Google dork: [inurl: "index. php? Id_categorie = "]" by www.Andabate.com©"
# Tested on: [windows 7]
# Demo site:
Http://www.habitech.fr/m_catalogue/index.php? Id_categorie = 10
Http://www.bulbargence.com/m_news/index.php? Id_categorie = 2
Http://www.sasvp.com/m_catalogue/index.php? Id_categorie = 30
# Error: SQL/DB Error -- [You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near AND clng. lang = "fr" at line 1]
# Database mysql is version 4.0
=============================================** FRENCH ** = ============================================
Password is encrypted by: md5 (md5 ($ pass ))