vendor site: 
product: mega-mall
bug:injection sql & full path disclosure
language: asp 
risk: high

injection sql (get):[sql][sql][sql][sql][sql] 

injection sql (post) : 

full path dislosure:[] 

laurent gaffi=E9 & benjamin moss=E9 

