[+] Multiple Sql Injection on CGR BRASIL CMS [+] Date: 21/04/2014 [+] Risk: High [+] Author: Felipe Andrian Peixoto [+] Vendor Homepage: http://www.cgrbrasil.com.br [+] Contact: felipe_andrian@hotmail.com [+] Tested on: Windows 7 and Linux [+] Exploit : http://host/print.php?id=[SQL Injection] [+] Exploit2 : http://host/print_noticia.php?id=[SQL Injection] [+] Exploit3 : http://host/pop_up.php?id=[SQL Injection] [+] Admin Page : http://host/admin