================= IUT-CERT ================= Title: Sheedravi CMS SQL Injection Vulnerability Vendor: www.sheedravi.com Dork: Design by Sheed Graphic Co Type: Input.Validation.Vulnerability (SQL Injection) Fix: N/A ================== nsec.ir ================= Description: ------------------ Sheedravi is a CMS producer in Iran. /template1/advancedsearch.aspx page in Sheedravi CMS product are vulnerable to SQL Injection vulnerability. Vulnerability Variant: ------------------ Injection "/template1/advancedsearch.aspx.aspx" in "txtAdvancedkeyword" POST parameter value:' or 1=1;-- '