================= IUT-CERT ================= Title: Sheedravi CMS SQL Injection Vulnerability Vendor: www.sheedravi.com Dork: Design by Sheed Graphic Co Type: Input.Validation.Vulnerability (SQL Injection) Fix: N/A ================== nsec.ir ================= Description: ------------------ Sheedravi is a CMS producer in Iran. /template1/advancedsearch.aspx page in Sheedravi CMS product are vulnerable to SQL Injection vulnerability. Vulnerability Variant: ------------------ Injection "/template1/advancedsearch.aspx.aspx" in "txtAdvancedkeyword" POST parameter value:' or 1=1;-- ' <script> and,... Solution: ------------------ Input validation of "txtAdvancedkeyword" POST parameter should be corrected. Credit: ------------------ Isfahan University of Technology - Computer Emergency Response Team Thanks to : M. Fereidounian, M. R. Faghani, N. Fathi,E. Jafari