# Exploit Title: [Same Team E-shop manager SQL Injection exploit]
# Date: [19-06-2011]
# Author: [Number 7]
# Software Link: [http://www.sameteam.com.tn/site/fr/eshop-manager.23.html]
# Tested on: [Linux]
_____________________________________________________________________________
Exploits:
Http://www.bkjia.com/path/catalogue.php? Id_shop = 7 [SQLI]
Http://www.bkjia.com/path/article.php? Id_article = 7 [SQLI]
Http://www.bkjia.com/path/banniere.php? Id_article = 7 [SQLI]
Http://www.bkjia.com/path/detail_news.php? Id_article = 7 [SQLI]
Http://www.bkjia.com/path/detail_produit.php? Id_shop = 3 & ref = 200308G [SQLI]
----------------------------------------_----------------------------------------
Use Havij: ^ D its fastest for the 4th version: D
_____________________________________________________________________________
########### Made in Tunisia + 216 ############
[~] Greetz tO: [Shichemt-älen/Ares/SWAT/S-MAN/Wx # all tunisian hackers]
[~] Home: Tunisia: ^ D
########### Made in Tunisia + 216 ############
Fixed: so many pages need to be filtered...