|=============================================================|
|-------------------In The Name Of God------------------------|
|
| Exploit Title: G.T. cms sql injection Vulnerability
|
| Exploit Author: Ashiyane Digital Security Team
|
| Vendor Homepage: http://www.manufacture.com.tw/
|
| Google Dork : site:tw inurl:exec/product.php?lg=E
|
| Tested on: Windows 10 ~~~> Google Chrome
|
| Date: 19/8/2017
|
| default admin page : target/admin
|====================================|
| Proof :
|
| http://www.octece.com/exec/product.php?lg=E
|
| http://www.longtsan.com.tw/exec/product.php?lg=E
|
| http://www.jgh.com.tw/exec/product.php?lg=E
|
| http://www.tongshen.com.tw/exec/product.php?lg=E
|
| http://www.chinghuaorchids.com.tw/exec/product.php?lg=E
|
|=============================================================|
| Discovered By : sir shahroukh
|=============================================================|