################################################################################??########
2 m0 [* y5 a8 w' S# $ w* y) Z& P7 N r+ k: w5 }
# Exploit Title : Net Ways Cms Sql Injection Vulnerability
5 f" |& t- V; `- F" f8 E#
3 j6 s; }* v( V. F6 O! L2 n# Author : IrIsT.Ir
" b5 x: _" s8 L# 4 g0 {4 Q* u. }8 s# R5 [+ o
# Discovered By : Am!r
/ {* n) Z) p% C- j- N3 @8 _; n' r# ) W, d s) r* ^" a5 _4 p
# Home : http://IrIsT.Ir/forum
1 O5 ]# d( r8 W1 B1 g& o" _#
' Z; e, J* f+ X M# ?( r# Software Link : http://www.netways.com/ www.political-security.com
5 r, Q- y- Y- Q' z _2 A9 x#
6 f) X$ g* n6 w6 [" J. o+ @% H: ^% F) u# Security Risk : High
2 j1 C' g b. \#
# m6 o+ _3 Y, M; G# Version : All Version
/ }0 v/ o5 m$ W+ y8 U, J3 q2 E# Q# 6 Z7 o+ t9 r! L! C P
# Tested on : GNU/Linux Ubuntu - Windows Server - win7
1 C: O0 j3 @* i& [& l; L9 W# , k% T, W( z k, A
# Dork : intext:"Designed & developed by NetWays"
. m# e9 R: | r1 u; j# 2 W& h9 D, F. t0 a& W& N
################################################################################??########
+ j. F* F+ s+ x0 w/ T/ L1 _+ [3 E# . Y! M3 E3 E, r! d0 a# `
# Expl0iTs :
6 ^$ m+ U. f! E: [# S' B4 ]; F6 f" z" D6 |9 w" `& P
# http://target.com/news.php?id=[Sql] 4 R1 D2 e$ t4 e; K" ?0 _& Y7 w
#
- ~: [8 t) W- r6 B3 C' x; _# , x$ A5 B0 x* ^* J9 @) A$ P
# D3mo : + ^9 b% O8 u1 P7 G3 d3 K$ r( V
# & h- P, n3 Q; a V, z% p6 C
# http://compagnieparento.com/news.php?id=7[Sql]
& l$ g, V) x% `; D& Y8 P5 J#
- u( x1 F' ?& v# i8 e" n################################################################################??######## 0 d' V5 G% h4 q) H
#
, Z; {0 P+ C* ?; H# Greats : B3HZ4D - nimaarek - Dead.Zone - C0dex - SpooferNinja - TaK.FaNaR - Nafsh - BestC0d3r
! `, X0 y7 J4 K# L$ }3 Z#
/ S5 a. @0 I4 M E, k8 p# 0x0ptim0us - TaK.FaNaR - m3hdi - F@rid - Siamak.Black - H4x0r - dr.tofan - skote_vahshat - d3c0d3r
]8 ? f- T1 @# ?#
& k4 w; h- ?, O. c4 c# Mr.Xpr & M.R.S.CO & Mr.Cicili & H-SK33PY & All Members In Www.IrIsT.Ir/forum ) ]" |* K- j7 S8 Q! w9 D
# + C7 C# J4 q$ j& x3 g* V/ @
################################################################################??######## |