Redtienda E-Commerce version 2.0 suffers from a remote SQL injection vulnerability.
254a66ed01d4fe65cc1f4ecee5e04fd56ef097f03a784bee9bf477ac65334d03
Title : Redtienda E-Commerce 2.0 SQLi Vulnerability
Date : 2/23/2012
Author : ITTIHACK (http://ittihack.com)
Vendor : http://www.redtienda.com/english
Software link : http://www.redtienda.com/english/getstarted.php
Free Demo : http://manager.redtienda.net
user:store - pass:beach65
Version : 2.0
Tested on : Windows 7
About : Redtienda is an online program that you use to create
and manage your own online store. There are both free
and commercial software.
Vulnerable File : pro.php
Exploit : http://site/path/pro.php?id=[SQLi]
Vulnerable websites : http://store.redtienda.net/pro.php?id=6
http://www.directfans.com/pro.php?id=138115
http://www.importdirecto.com/pro.php?id=246674
Solution : I contacted the developers, hope to be fixed as soon as possible
Special Greating to: alex m7md