################################################################################??########
- q# u! W; G! h }2 k# x6 F# 8 B" u0 `5 ], I( b$ ^
# Exploit Title : Net Ways Cms Sql Injection Vulnerability
' N4 X* V$ Y3 \. d. ^1 j" c; a' K9 S#
8 q$ Y! l, v7 S9 x: f& V# Author : IrIsT.Ir
4 l& O& D6 b8 \# & U5 K! e2 z" A8 |; \
# Discovered By : Am!r 2 A/ A# B: B" n! K" }7 u+ x/ X
# 0 k5 e0 _& A+ o: M5 X
# Home : http://IrIsT.Ir/forum + B' W) N' x: ]4 O8 h
#
) D; x6 o5 d4 G8 n: u/ j6 T# Software Link : http://www.netways.com/ www.political-security.com
0 V& y3 _ A+ |+ I#
; R$ M9 u! z. V: }5 D8 I: u# Security Risk : High ! X' K2 u( v% d1 s7 o" g) \
#
( ]5 X4 M( U4 v& S/ r# Version : All Version
7 w% r$ I9 [% `' N) ^/ B1 \#
! y' }2 u% X4 ^* ~2 {# Tested on : GNU/Linux Ubuntu - Windows Server - win7 + M% ^$ S! Q1 @+ E$ T; _. z+ E
#
* M5 T1 v! g/ E) n! l) j, k# Dork : intext:"Designed & developed by NetWays" ! K# @' G) h" C( U0 R. T; L* m
# $ P/ ?" w, o+ ~
################################################################################??########
9 ^6 J/ u- U9 `- h#
" W8 ?8 L; ]# c- D& h; G# Expl0iTs : # \% [' D6 E: y# {5 _
#
# R4 F4 H) [3 w7 N: k6 u# http://target.com/news.php?id=[Sql]
( j% P7 p4 o6 K#
2 O* j4 {! B4 c7 x) j8 ?# $ L J0 ]/ r* O7 R: ?3 H- h
# D3mo : % B: L9 E. r0 I( e) H! q
#
1 w0 W. y5 o& \- q' A! W3 T# http://compagnieparento.com/news.php?id=7[Sql]
" V1 m) S& F( {5 v- j, |1 u1 t5 H#
1 q$ m: K+ S# V. x6 ^################################################################################??######## 4 v: y1 r) q6 p; t! k u/ _
#
2 [0 [& Y9 }% L2 ?# Greats : B3HZ4D - nimaarek - Dead.Zone - C0dex - SpooferNinja - TaK.FaNaR - Nafsh - BestC0d3r , \) t- }7 K, K- \+ F6 l9 o
#
2 i( |# p: O9 C+ i y8 ]# 0x0ptim0us - TaK.FaNaR - m3hdi - F@rid - Siamak.Black - H4x0r - dr.tofan - skote_vahshat - d3c0d3r , ]% _: u& w, S0 x. v
#
* W+ v. D. R C7 q1 s# Mr.Xpr & M.R.S.CO & Mr.Cicili & H-SK33PY & All Members In Www.IrIsT.Ir/forum
+ I9 _4 c/ [, x9 D#
: r& q( n# |2 ~5 F. A! g5 ^################################################################################??######## |