Dealer Express Auto Sales CMS SQLi by #cehov RST Platform: Web App Sellers of CMS: http://www.dealerexpress.net/page.php Type: Sql injection, privilege escalation Admin url: http://www.domain.com/CarDealer/admin/ Date of begin: 24 feb 2015 Dork 1: "powered by dealer express" Dork 2: "result.php?makeid=" Example: http://www.domain.com/cardealer/results.php?makeid=55 http://www.domain.com/CarDealer/results.php?makeid=8 The makeid is not the only, there are multiple vuln. in this auto cms. Have fun RST.