################################################################################??######## 6 D3 c' k7 }4 I, S
#
8 \# o/ ^* v" x# Exploit Title : Net Ways Cms Sql Injection Vulnerability ( T) i6 y* a1 p% M5 `, d9 z# I
# & ~" f' N# s; q! I
# Author : IrIsT.Ir . H0 ^# ?/ h3 z% Z
# / `2 d- r- A7 J3 l4 L8 }6 N
# Discovered By : Am!r
, M& t( T8 ?" o! B- h$ k% `0 V# U#
- K" n! ^. F1 P, A, y7 a# Home : http://IrIsT.Ir/forum
% _/ B/ H% k( T4 J' j2 j4 ]) Z# % v0 {7 Y4 }& m/ ^* m6 V
# Software Link : http://www.netways.com/ www.political-security.com6 E7 r, k! Z1 _* Q5 E
# 2 v3 P0 i- A$ _( f3 x, t" h: g
# Security Risk : High 4 o, u1 V& e% X1 ~9 F1 N: u; J x i
#
$ U& Q3 U$ _& N( K. L# Version : All Version 3 k/ O2 L/ e' X4 ^! A
#
5 p; G( q7 R4 a+ J0 U# Tested on : GNU/Linux Ubuntu - Windows Server - win7
; f: R- n. x" T' ~ B#
8 h6 |. \2 S/ `: y$ X# Dork : intext:"Designed & developed by NetWays" 1 s1 n3 [ L: N0 [* ~
# , g- X4 }4 P) e) y
################################################################################??######## + ~2 G; b( |& Z& E3 Q ^- k
#
& c8 b+ R& g% @2 D# Expl0iTs : $ ?+ P4 r' x2 Y: u @
#
) T3 Z% M5 h$ ^* ]5 W* N/ E# http://target.com/news.php?id=[Sql]
2 f- U. D5 B# u0 f' t% S#
5 U; h+ M6 B& E#
: [. `0 U/ \& I. n! F _# D3mo : # L# L* E* A" D* Z
# " Q& m$ o! X u$ p* E: s' r7 N# R* K
# http://compagnieparento.com/news.php?id=7[Sql]
B6 J5 `# d5 D' t2 r# + T6 |6 o! f @( A+ H' n
################################################################################??######## 0 D( k3 o. t! ~' c; G
# - F0 b" c* S; n) m/ h
# Greats : B3HZ4D - nimaarek - Dead.Zone - C0dex - SpooferNinja - TaK.FaNaR - Nafsh - BestC0d3r
1 |6 i- _" e: H* E: i9 ]8 y' G" n# . T) ~& X/ C2 P
# 0x0ptim0us - TaK.FaNaR - m3hdi - F@rid - Siamak.Black - H4x0r - dr.tofan - skote_vahshat - d3c0d3r 3 t) b( ]- g, a
# : I/ \+ |& i# H! K" Y3 e+ A! M
# Mr.Xpr & M.R.S.CO & Mr.Cicili & H-SK33PY & All Members In Www.IrIsT.Ir/forum }" M: ^3 [! ]' C( n, G
# 0 Q3 H3 e- [! p: E5 y6 G
################################################################################??######## |