[+] Sql Injection on CMS PUNTOPY
[+] Date: 06/05/2014
[+] Risk: High
[+] Author: Felipe Andrian Peixoto
[+] Vendor Homepage: http://www.grupopuntopy.com/
[+] Contact: felipe_andrian@hotmail.com
[+] Tested on: Windows 7 and Linux
[+] Vulnerable File: novedad.php
[+] Exploit : http://host/novedad.php?ID=[SQL Injection]
[+] PoC: http://www.ipale.com.py/pisos-revestimientos/novedad.php?id=51
http://www.ztdistribuciones.com.py/novedad.php?ID=8
http://www.seguroslaagricola.com.py/novedad.php?id=10
[+] Admin Page: http://host/admin/