Wednesday, January 4, 2012

Wall of Shame

Every once in a while I notice things while I try to conduct personal business.
Often times I try to conduct the web app owners. Often my emails are ignored or the owners reply that it's not a problem.

Original URL: http://www.stactionpro.com/picatinny-rail-clamp-p-76.html
---------------------------------------------------------------------------------------------------------------------------------
144 Table './action_zencart/products' is marked as crashed and last (automatic?) repair failed
in:
[select p2c.categories_id from products p, products_to_categories p2c where p.products_id = '76' and p.products_status = '1' and p.products_id = p2c.products_id limit 1]
---------------------------------------------------------------------------------------------------------------------------------

Yes dear reader, they are using zencart, yes they did not parametarize their queries. Is it exploitable? Pretty good chance, but that's not for me to find out. Now I need to find another vendor to buy a dual clamp rail from...


No comments:

Post a Comment